ci(pre-commit): protect main and versions/ branches from direct commits - #51
Merged
Merged
Conversation
Adds the no-commit-to-branch hook from pre-commit-hooks, blocking direct commits to main and any versions/* branch. Runs on pre-commit.ci and locally via `pre-commit run`. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
always_run is already the hook's shipped default, but setting it explicitly documents that this hook intentionally ignores any files/exclude/types filtering (and would still allow --allow-empty commits through). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
no-commit-to-branch would otherwise fail every push to main once this merges: CI checks out a real local branch literally named `main` for push events, so the hook would always fire. It's a client-side guard for a human running `git commit`/`git push` locally (or via installed git hooks) -- not something a full "run every hook" CI invocation should re-evaluate after the fact. Skips it there via SKIP=no-commit-to-branch; the hook itself is untouched and still fully active locally. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…anch Appends no-commit-to-branch to any SKIP a developer already has set (e.g. via their shell) rather than overwriting it wholesale, matching the same fix applied in response to Copilot review feedback on GalacticDynamics/coordinax#885. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Addresses Copilot review feedback on GalacticDynamics/galax#847: the comment said "CI checks out the real main branch," but the skip applies unconditionally, including local `nox -s lint` runs -- which is correct (a CI-only skip would leave the same false failure for any local dev running the full suite while on `main`). Fixes the wording to match the actual, intended behavior instead of narrowing it. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
no-commit-to-branchhook from pre-commit-hooks to.pre-commit-config.yamlmain(--branch main) and anyversions/*maintenance branch (--pattern ^versions/.*) from direct commitspre-commit run) and on pre-commit.ciTest plan
argsshape against the same change already merged in unxt#929, coordinax#881, jaxmore#26, quaxed#213, quax-blocks#64🤖 Generated with Claude Code