Skip to content

ci(pre-commit): protect main and versions/ branches from direct commits - #51

Merged
nstarman merged 5 commits into
mainfrom
add-no-commit-to-branch
Sep 15, 2026
Merged

nstarman merged 5 commits into
mainfrom
add-no-commit-to-branch

Conversation

@nstarman

Copy link
Copy Markdown
Contributor

Summary

  • Adds the no-commit-to-branch hook from pre-commit-hooks to .pre-commit-config.yaml
  • Protects main (--branch main) and any versions/* maintenance branch (--pattern ^versions/.*) from direct commits
  • Runs both locally (pre-commit run) and on pre-commit.ci

Test plan

🤖 Generated with Claude Code

nstarman and others added 5 commits September 15, 2026 10:23
Adds the no-commit-to-branch hook from pre-commit-hooks, blocking
direct commits to main and any versions/* branch. Runs on pre-commit.ci
and locally via `pre-commit run`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
always_run is already the hook's shipped default, but setting it
explicitly documents that this hook intentionally ignores any
files/exclude/types filtering (and would still allow --allow-empty
commits through).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
no-commit-to-branch would otherwise fail every push to main once this
merges: CI checks out a real local branch literally named `main` for
push events, so the hook would always fire. It's a client-side guard
for a human running `git commit`/`git push` locally (or via installed
git hooks) -- not something a full "run every hook" CI invocation
should re-evaluate after the fact. Skips it there via
SKIP=no-commit-to-branch; the hook itself is untouched and still fully
active locally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…anch

Appends no-commit-to-branch to any SKIP a developer already has set
(e.g. via their shell) rather than overwriting it wholesale, matching
the same fix applied in response to Copilot review feedback on
GalacticDynamics/coordinax#885.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: the
comment said "CI checks out the real main branch," but the skip
applies unconditionally, including local `nox -s lint` runs -- which
is correct (a CI-only skip would leave the same false failure for any
local dev running the full suite while on `main`). Fixes the wording
to match the actual, intended behavior instead of narrowing it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nstarman nstarman added this to the v1.7.0 milestone Sep 15, 2026
@nstarman
nstarman merged commit 0c38c5f into main Sep 15, 2026
23 checks passed
@nstarman
nstarman deleted the add-no-commit-to-branch branch September 15, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant