Repository navigation
Conversation
prek 0.5.3 is the newest release outside the 7-day exclude-newer cooldown. It is a single binary, so pre-commit's Python dependencies (cfgv, identify, nodeenv, pyyaml, virtualenv and theirs) leave uv.lock. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
prek ignores minimum_pre_commit_version, so the floor moves to minimum_prek_version, which prek enforces. `language: system` is prek's name for what pre-commit 4.4 calls `unsupported`; prek reads both. prek replaces the pre-commit-hooks hooks with built-in Rust versions unless a hook sets its language. On a corpus of edge cases those versions diverge from the pinned v6.0.0 hooks (unknown YAML tags, TOML 1.1 syntax, an empty JSON file, a BOM or NaN in JSON, a lone `=======` during a merge, vertical tabs and CR-only line endings), so each hook sets `language: python` and keeps the pinned implementation, which fails and fixes the same files pre-commit did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The job keeps its id, the required status check. prek comes from the locked dev group (`uv run --locked --only-dev`), so CI runs the version in uv.lock rather than the one j178/prek-action would download. The hook cache moves to prek's home, set explicitly so prek and the cache step agree, and its key adds uv.lock, which pins prek and the uv that builds the hook environments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
prek is 0.x, so a minor release may change how the hooks run; like a new ruff rule, that must not hold up the runtime floor bumps. The pre-commit ecosystem entry stays: Dependabot only reads and rewrites .pre-commit-config.yaml, which prek reads unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Setup installs the Git hook with `uv run prek install`, and a clone whose hook pre-commit installed is told to pass --force: otherwise prek keeps that hook as pre-commit.legacy and runs it too, and it fails once pre-commit is gone from .venv. `uv run prek run --all-files` runs every hook as CI does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
prek builds the pre-commit-hooks environment with whichever Python uv picks first, ignoring .python-version, so check-json and check-toml could parse with a newer json or tomllib than the project's 3.11. default_language_version pins it to 3.11, the interpreter pre-commit used when run from .venv. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The cache key hashed uv.lock with no restore-keys, so every uv.lock change, including each Dependabot uv bump, started from an empty cache. The key now hashes the config and uv.lock separately, and restore-keys falls back to the newest cache for the same config; prek reuses the environments that still match and the new key is saved. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Dependency Security AuditScanned: pyproject.toml dependencies + dev group, resolved at Python 3.10 (the current resolution, and the lowest versions the published specs permit under each pydantic major) ✅ No known vulnerabilities found. Both the resolved dependency set and the lowest versions the published specs permit are clean at HIGH and CRITICAL. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linear issues
.pre-commit-config.yaml.Targets
main; not stacked on #136–#144.Why
The SDK upgrade guide (PER-16336) and the team's tooling standard use prek, a Rust runner that reads the same
.pre-commit-config.yaml.What changed
pyproject.toml: the dev group pinsprek==0.5.3instead ofpre-commit==4.6.2. 0.5.3 is the newest release outside the 7-dayexclude-newercooldown. Inuv.lock, re-locking removed pre-commit and its dependencies (cfgv, distlib, filelock, identify, nodeenv, platformdirs, python-discovery, pyyaml, virtualenv). Nothing in the repo imports them..pre-commit-config.yamlkeeps the same file name, the same 17 hooks and the same revs:minimum_prek_version: "0.5.3"replacesminimum_pre_commit_version, which prek ignores.language: systeminstead oflanguage: unsupported, which prek treats as an alias ofsystem.language: python. Without it, prek runs its own Rust versions of those hooks. Those accept unknown YAML tags, TOML 1.1 and empty JSON files, which v6.0.0 rejects.default_language_version: python: "3.11": prek builds the pre-commit-hooks environment with whichever Python uv picks first and ignores.python-version. pre-commit used the 3.11 from.venv..github/workflows/pre-commit.yml):pre-commit, the required status check.uv run --locked --only-dev prek run --all-files --show-diff-on-failure --color=always, so the prek version comes fromuv.lock.PREK_HOME(~/.cache/prek). The cache key is the runner OS, the Python version, the config hash and theuv.lockhash.restore-keysfalls back to the newest cache for the same config, so auv.lockbump reuses the hook environments.prekis added to thelint-toolsgroup, so its updates get their own PR. Thepre-commitecosystem entry stays, because Dependabot only parses the config file and rewritesrevand the# frozen:comment.uv run prek installanduv run prek run --all-files, and adds a note for clones whose Git hook was installed by pre-commit.The
pre-commitmentions that remain name one of these:pre-commit/pre-commit-hooksrepository.git/hooks/pre-commitpathBehaviour changes
SDK: none. Nothing under
permit/ortests/changed.Contributor tooling:
uv run prek installanduv run prek run --all-filesreplace the pre-commit commands..git/hooks/pre-commitwas installed by pre-commit needsuv syncand thenuv run prek install --forceonce. Without--force, prek keeps the old hook aspre-commit.legacyand runs it too, and every commit fails with "No module named pre_commit".lint-tools) instead of joiningminor-and-patch.How it was tested
Same results on a clean tree. pre-commit 4.6.2 (main's lock, at ef80ae2) and prek 0.5.3 (this branch) both ran the same 17 hooks: 16 Passed and check-xml Skipped, with identical output line for line.
Planted failures. One failure at a time; both runners failed the same hooks for each:
evalPLANTED=1tehConfig checks:
language: pythonfrom check-json, check-toml and check-yaml makes those three planted inputs pass, because prek then uses its Rust versions.minimum_prek_version: "9.0.0"stops prek with "prekversion9.0.0or newer is required".default_language_version, an empty PREK_HOME got a hook environment on free-threaded CPython 3.14.7. With it, the environment uses 3.11.14. A cache that already holds the 3.14 environment gets a new 3.11 one.Git hook, in a throwaway clone.
uv run prek installblocked a commit with trailing whitespace andeval(trim trailing whitespace, ruff check and ruff format failed) and allowed a clean commit. The CONTRIBUTING note reproduced: without--forcethe commit failed with "No module named pre_commit"; with--forceit passed.Suites and linters:
uv lock --check: passes.uv run --locked --only-dev prek run --all-fileswith an empty PREK_HOME: all hooks pass.tests/test_typing_surface.py: 3 passed on both lanes..github/scriptstests: 108 passed.skills/tests: 86 passed, 1 skipped (a tool missing from PATH).Owner actions before merge
pre-commitcheck is green.language: pythonon the 12 pre-commit-hooks hooks. This keeps the v6.0.0 behaviour; prek's Rust versions would save about 0.6 s per warm run.prekin Dependabot'slint-toolsgroup. Main had no uv group naming pre-commit; it fell underminor-and-patch.uv syncanduv run prek install --forceonce.🤖 Generated with Claude Code