BUILD-12282: Upgrade pre-commit CI to gh-action_pre-commit@v2 - #345
Conversation
ac1041e to
4709347
Compare
4709347 to
4125b3e
Compare
4125b3e to
84e1668
Compare
Code Review ✅ Approved 4 resolved / 4 findingsUpgrades pre-commit CI to gh-action_pre-commit ✅ 4 resolved✅ Quality: pre-commit no longer runs on pushes to branch-* maintenance branches
✅ Bug: sonar-xs runner cannot run the docker_image shellcheck hook
✅ Bug: Vault-authenticating job has id-token: write but no environment:
✅ Quality: Local shellcheck hook silently uses whatever shellcheck is on PATH
Implementation Status ◻️ 4 of 5 objectives covered◻️ BUILD-12282 - 4 of 5 objectives coveredThis PR covers routing pip and npm hook installs through Repox, configuring workflow permissions, updating the README, and keeping nodeenv on nodejs.org/dist. Other objectives on this issue, possibly covered elsewhere:
✅ 4 covered here
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
84e1668 to
afb1ad3
Compare
Align the workflow with the v2 README skeleton: sonar-xs, job-level id-token permissions, event defaults, and bundled Repox auth. Run shellcheck from mise.toml (0.11.0) instead of the docker_image hook, which sonar-xs cannot execute. Also cover push to branch-*.
afb1ad3 to
5799a72
Compare
|



BUILD-12282: Upgrade pre-commit CI to gh-action_pre-commit@v2
Summary
.github/workflows/pre-commit.ymlto the v2 README skeletonpermissions(id-token: write,contents: read) andconcurrency(cancel-in-progress: true); remove job-levelpermissionspull_request,merge_group, andpushto the GitHub default branchsonar-xsactions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1withfetch-depth: 0SonarSource/gh-action_pre-commit@v2extra-args,ignore-failurehelpers, and caller-side Repox/registry auth (bundled in v2)language: systemshellcheck with gruntwork-io hook; mise already providesshellcheckDepends on Vault Artifactory reader grants from the re-terraform-aws-vault order update.
Test plan
--all-files