Skip to content

[no-ci] ci: run pre-commit on Linux and Windows with Dependabot hook updates - #2994

Merged
rwgk merged 5 commits into
mainfrom
rwgk/maint/pre-commit-actions
Oct 2, 2026
Merged

rwgk merged 5 commits into
mainfrom
rwgk/maint/pre-commit-actions

Conversation

@rwgk

@rwgk rwgk commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Related to #2652.

Run pre-commit directly on every PR update, including drafts, using hosted Linux
and Windows runners with Python 3.14. Preserve the existing Windows job's secret
scan, skip lychee and the local hook-installation reminder, and cache environments
by OS, resolved Python version, and hook configuration. Push checks cover main;
copy-pr-bot's pull-request/* refs do not trigger this workflow. Manual dispatch
supports branch testing.

Use Dependabot's native pre-commit support for grouped monthly hook revision
updates, retaining SHA pins and frozen version comments. Hook updates and both
GitHub Actions update entries use the CI/CD and dependencies labels, without
an automatic assignee or milestone. Allow hook repository URLs only so additional_dependencies pins
stay unchanged. Exclude lychee so its hook revision, version argument, and CI
binary can be updated together. Dependabot opens regular PRs; its first hosted
hook-update run can be verified after this configuration reaches main.

The next stack layer (#2993) removes the old Windows job and adds dedicated
PR/nightly link checks and migration guidance. Keep pre-commit.ci installed and
required until the replacements are merged and green. This implementation PR
stays draft; heavyweight CI remains under /ok to test <full-SHA> control.

Validation before the monthly/metadata refinements, at revision
2e3534ee4e004a8242096917248e152f37ba90cc: Dependabot schema validation, the
native Dependabot configuration check,
actionlint, and all repository pre-commit hooks pass. Local hooks were checked in fresh Python 3.14 environments
through PATH Pixi. Hosted Linux/Windows all-files checks pass in both the
PR-triggered run
and manual dispatch,
including secret scans; both runners resolved CPython 3.14.7. The pip upgrade is
retained. Temporary branch bootstrap triggers have been removed.

The monthly/metadata refinement passes git diff --check; the full validation
suite was not repeated for this configuration-only update.

Checklist

  • New or existing tests cover these changes.
  • The documentation is up to date with these changes (migration guide in the next stack layer).

@rwgk rwgk added this to the cuda.core next milestone Oct 1, 2026
@rwgk rwgk added the CI/CD CI/CD infrastructure label Oct 1, 2026
@rwgk rwgk self-assigned this Oct 1, 2026
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@mdboom mdboom left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For the autoupdate part, can't we just use dependabot? It supports updating pre-commit hooks?

There is a precommit-windows job in ci.yml that is now redundant to this that should be removed.

key: pre-commit-${{ runner.os }}-${{ steps.python.outputs.python-version }}-${{ hashFiles('.pre-commit-config.yaml') }}

- name: Install pre-commit
run: python -m pip install --upgrade pip pre-commit

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a specific reason to always upgrade pip? I think in this clean environment we always get the latest version anyway. (Maybe the caching means it might be stale)?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd prefer to keep the upgrade: it is very quick when pip is already current and removes a doubt.

Rationale:

I asked codex to look a little deeper. It found:

A clean environment doesn't guarantee that it will always be a no-op. With our inputs, setup-python selects a Python installation and doesn't automatically upgrade pip. Python's bundled pip can lag the separately released version on PyPI. The pre-commit cache contains hook environments, rather than the host's pip, so that cache isn't the explanation.

codex also explained:

The original workflow kept the pip upgrade from the existing Windows job so that pre-commit is installed with the current pip. There's no demonstrated need for a newer pip today. In the earlier validation run, both Linux and Windows already had pip 26.2.1, so the upgrade was a no-op.

Comment thread .github/workflows/pre-commit.yml Outdated
id: python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.13'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not 3.14?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changed to 3.14.

codex explained:

The original workflow kept Python 3.13 from the existing Windows pre-commit job. There wasn't a specific requirement to stay on 3.13.

@rwgk rwgk changed the title ci: run pre-commit on Linux and Windows with quarterly hook updates ci: run pre-commit on Linux and Windows with Dependabot hook updates Oct 2, 2026
@rwgk

rwgk commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

For the autoupdate part, can't we just use dependabot? It supports updating pre-commit hooks?

Yes, much better, and done. — codex explained that it missed that alternative initially.

I was wondering myself, but you actually got to reviewing this PR before I got to it myself.

@rwgk rwgk changed the title ci: run pre-commit on Linux and Windows with Dependabot hook updates [no-ci] ci: run pre-commit on Linux and Windows with Dependabot hook updates Oct 2, 2026
@rwgk
rwgk force-pushed the rwgk/maint/pre-commit-actions branch from 9519f48 to 7464d45 Compare October 2, 2026 17:00
@rwgk
rwgk marked this pull request as ready for review October 2, 2026 17:01
@rwgk

rwgk commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

There is a precommit-windows job in ci.yml that is now redundant to this that should be removed.

The removal is in the follow-up PR #2993 (change in .github/workflows/ci.yml), including the old job's dependency and success check in the aggregate CI gate.

@rwgk rwgk mentioned this pull request Oct 2, 2026
2 tasks done

@mdboom mdboom left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These changes all look good, but we are still missing this from the last review:

"There is a precommit-windows job in ci.yml that is now redundant to this that should be removed."

@rwgk

rwgk commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Merging while still working on the stacked PRs above: it's an easy opportunity to validate the new workflow in the wild before we fully rely on it.

@rwgk
rwgk merged commit c3c2678 into main Oct 2, 2026
28 checks passed
@rwgk
rwgk deleted the rwgk/maint/pre-commit-actions branch October 2, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI/CD CI/CD infrastructure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants