[no-ci] ci: run pre-commit on Linux and Windows with Dependabot hook updates - #2994
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
mdboom
left a comment
There was a problem hiding this comment.
For the autoupdate part, can't we just use dependabot? It supports updating pre-commit hooks?
There is a precommit-windows job in ci.yml that is now redundant to this that should be removed.
| key: pre-commit-${{ runner.os }}-${{ steps.python.outputs.python-version }}-${{ hashFiles('.pre-commit-config.yaml') }} | ||
|
|
||
| - name: Install pre-commit | ||
| run: python -m pip install --upgrade pip pre-commit |
There was a problem hiding this comment.
Is there a specific reason to always upgrade pip? I think in this clean environment we always get the latest version anyway. (Maybe the caching means it might be stale)?
There was a problem hiding this comment.
I'd prefer to keep the upgrade: it is very quick when pip is already current and removes a doubt.
Rationale:
I asked codex to look a little deeper. It found:
A clean environment doesn't guarantee that it will always be a no-op. With our inputs, setup-python selects a Python installation and doesn't automatically upgrade pip. Python's bundled pip can lag the separately released version on PyPI. The pre-commit cache contains hook environments, rather than the host's pip, so that cache isn't the explanation.
codex also explained:
The original workflow kept the pip upgrade from the existing Windows job so that pre-commit is installed with the current pip. There's no demonstrated need for a newer pip today. In the earlier validation run, both Linux and Windows already had pip 26.2.1, so the upgrade was a no-op.
| id: python | ||
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | ||
| with: | ||
| python-version: '3.13' |
There was a problem hiding this comment.
Changed to 3.14.
codex explained:
The original workflow kept Python 3.13 from the existing Windows pre-commit job. There wasn't a specific requirement to stay on 3.13.
Yes, much better, and done. — codex explained that it missed that alternative initially. I was wondering myself, but you actually got to reviewing this PR before I got to it myself. |
9519f48 to
7464d45
Compare
The removal is in the follow-up PR #2993 (change in |
mdboom
left a comment
There was a problem hiding this comment.
These changes all look good, but we are still missing this from the last review:
"There is a precommit-windows job in ci.yml that is now redundant to this that should be removed."
|
Merging while still working on the stacked PRs above: it's an easy opportunity to validate the new workflow in the wild before we fully rely on it. |
Description
Related to #2652.
Run pre-commit directly on every PR update, including drafts, using hosted Linux
and Windows runners with Python 3.14. Preserve the existing Windows job's secret
scan, skip lychee and the local hook-installation reminder, and cache environments
by OS, resolved Python version, and hook configuration. Push checks cover
main;copy-pr-bot's
pull-request/*refs do not trigger this workflow. Manual dispatchsupports branch testing.
Use Dependabot's native pre-commit support for grouped monthly hook revision
updates, retaining SHA pins and frozen version comments. Hook updates and both
GitHub Actions update entries use the
CI/CDanddependencieslabels, withoutan automatic assignee or milestone. Allow hook repository URLs only so
additional_dependenciespinsstay unchanged. Exclude lychee so its hook revision, version argument, and CI
binary can be updated together. Dependabot opens regular PRs; its first hosted
hook-update run can be verified after this configuration reaches
main.The next stack layer (#2993) removes the old Windows job and adds dedicated
PR/nightly link checks and migration guidance. Keep pre-commit.ci installed and
required until the replacements are merged and green. This implementation PR
stays draft; heavyweight CI remains under
/ok to test <full-SHA>control.Validation before the monthly/metadata refinements, at revision
2e3534ee4e004a8242096917248e152f37ba90cc: Dependabot schema validation, thenative Dependabot configuration check,
actionlint, and all repository pre-commit hooks pass. Local hooks were checked in fresh Python 3.14 environments
through PATH Pixi. Hosted Linux/Windows all-files checks pass in both the
PR-triggered run
and manual dispatch,
including secret scans; both runners resolved CPython 3.14.7. The pip upgrade is
retained. Temporary branch bootstrap triggers have been removed.
The monthly/metadata refinement passes
git diff --check; the full validationsuite was not repeated for this configuration-only update.
Checklist