-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.pre-commit-config.yaml
More file actions
88 lines (85 loc) · 3.57 KB
/
Copy path.pre-commit-config.yaml
File metadata and controls
88 lines (85 loc) · 3.57 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
repos:
- repo: https://github.com/astral-sh/ruff-pre-commit
# v0.10.5 dep-cycle: aligned to pyproject.toml dev group's
# "ruff>=0.15.21" pin so local pre-commit == CI == dev-install.
#
# CO-EVOLUTION CONTRACT: when bumping the ruff dep in
# pyproject.toml, bump this `rev:` in the SAME commit. These
# three sources of truth MUST stay synchronized:
# 1. pyproject.toml dev = ["ruff>=X.Y.Z", ...]
# 2. THIS FILE: rev: vX.Y.Z
# 3. CI uv.lock: resolved ruff version
# dependabot's github-actions updater handles (2) automatically
# only when CI bumps it via dependabot/github_actions; if you
# bump ruff via dependabot/python:uv, you MUST update (2) here
# manually.
rev: v0.15.21
hooks:
- id: ruff
args: [--fix]
- id: ruff-format
# Workspace-aware mypy hook. We use a local hook that runs
# ``uv run mypy`` instead of the pre-commit/mirrors-mypy remote
# hook, because the remote hook builds a separate hook venv that
# does NOT include the workspace members (gw2_core, gw2_evtc_parser,
# gw2_analytics, gw2_api_client). Those members are declared as
# editable installs in the root ``pyproject.toml`` via
# ``[tool.uv.sources]``, so the project's own ``uv`` venv has them
# but a freshly-built hook venv does not. The result was that the
# remote hook fired ``import-not-found`` for ``from gw2_core import
# ...`` on every commit, requiring ``--no-verify`` to bypass.
#
# Running ``uv run mypy`` from the repo root reuses the project's
# full workspace venv, so:
# - editable workspace members resolve correctly
# - third-party dev deps (pytest, etc.) are stubbed properly
# - ``--disable-error-code=misc`` is no longer needed (the
# "Untyped decorator" and "Class cannot subclass X" noise
# categories were artifacts of the missing-stubs hook venv)
#
# Prereq: the developer must have ``uv`` on ``$PATH`` when running
# ``git commit`` (the project's standard toolchain already requires
# this for ``uv sync`` / ``uv run`` workflows, so no new install
# step is needed).
- repo: local
hooks:
- id: mypy
name: mypy (workspace-aware via uv run)
entry: uv run mypy --no-incremental
language: system
types: [python]
files: ^(libs|apps)/.*\.py$
require_serial: true
# ``--no-incremental`` is required so mypy re-checks the
# whole affected subpackage rather than relying on a stale
# ``.mypy_cache`` left behind by a previous full-project
# ``uv run mypy libs apps`` run. The CI invocation also
# uses ``--no-incremental`` for the same reason.
# Phase 5.5: secrets scanning via detect-secrets.
# Baseline must be regenerated via:
# detect-secrets scan > .secrets.baseline
# after any change that intentionally introduces a secret-like
# pattern (e.g. a test fixture key). The baseline file is the
# allowlist for pre-commit to distinguish real secrets from
# false positives.
- repo: https://github.com/Yelp/detect-secrets
rev: v1.5.0
hooks:
- id: detect-secrets
args: ["--baseline", ".secrets.baseline"]
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v5.0.0
hooks:
- id: check-yaml
- id: check-json
- id: check-toml
- id: end-of-file-fixer
exclude: ^CHANGELOG.md$
- id: trailing-whitespace
- id: check-merge-conflict
- id: check-added-large-files
args: ["--maxkb=1000"]
- id: check-case-conflict
- id: mixed-line-ending
args: ["--fix=lf"]
- id: debug-statements