From d7b0c6ec836929d7664d1488726eb7ba4ab53a03 Mon Sep 17 00:00:00 2001 From: nstarman Date: Tue, 15 Sep 2026 10:23:35 -0400 Subject: [PATCH 1/2] ci(pre-commit): protect main and versions/ branches from direct commits Adds the no-commit-to-branch hook from pre-commit-hooks, blocking direct commits to main and any versions/* branch. Runs on pre-commit.ci and locally via `pre-commit run`. Co-Authored-By: Claude Sonnet 5 --- .pre-commit-config.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 2495d18..77d90f6 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -23,6 +23,8 @@ repos: - id: mixed-line-ending - id: name-tests-test args: ["--pytest-test-first"] + - id: no-commit-to-branch + args: ["--branch", "main", "--pattern", "^versions/.*"] - id: requirements-txt-fixer - id: trailing-whitespace From ffafd7d0d3dee0351dead644db375a25274d273b Mon Sep 17 00:00:00 2001 From: nstarman Date: Tue, 15 Sep 2026 10:33:17 -0400 Subject: [PATCH 2/2] ci: explicitly set always_run: true on no-commit-to-branch always_run is already the hook's shipped default, but setting it explicitly documents that this hook intentionally ignores any files/exclude/types filtering (and would still allow --allow-empty commits through). Co-Authored-By: Claude Sonnet 5 --- .pre-commit-config.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 77d90f6..eb54959 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -25,6 +25,7 @@ repos: args: ["--pytest-test-first"] - id: no-commit-to-branch args: ["--branch", "main", "--pattern", "^versions/.*"] + always_run: true - id: requirements-txt-fixer - id: trailing-whitespace