From 5799a72e0b834955ddb6dea0a174b60534b45459 Mon Sep 17 00:00:00 2001 From: Mate Molnar Date: Wed, 9 Sep 2026 13:08:16 +0200 Subject: [PATCH] BUILD-12282: Upgrade pre-commit CI to gh-action_pre-commit@v2 Align the workflow with the v2 README skeleton: sonar-xs, job-level id-token permissions, event defaults, and bundled Repox auth. Run shellcheck from mise.toml (0.11.0) instead of the docker_image hook, which sonar-xs cannot execute. Also cover push to branch-*. --- .github/workflows/pre-commit.yml | 28 ++++++++++++++++------------ .pre-commit-config.yaml | 8 ++++++-- 2 files changed, 22 insertions(+), 14 deletions(-) diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index 9a60cfb5..0e15f336 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -1,18 +1,22 @@ -name: Pre-commit Checks on: pull_request: -permissions: - id-token: write - contents: write + merge_group: + push: + branches: + - master + - branch-* + +name: pre-commit + jobs: pre-commit: - runs-on: warp-custom-ubuntu-24-04 + runs-on: sonar-xs + permissions: + id-token: write + contents: read steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - - uses: ./config-npm - - uses: ./config-pip - - uses: SonarSource/gh-action_pre-commit@2ddc0c7fdabce0adfaaa4075a17690972ed9961a # 1.2.0 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - extra-args: > - --from-ref=origin/${{ github.event.pull_request.base.ref }} - --to-ref=${{ github.event.pull_request.head.sha }} + fetch-depth: 0 + - uses: SonarSource/mise-action-wrapper@v1 + - uses: SonarSource/gh-action_pre-commit@v2 diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index c4f530fd..a9eb1753 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -17,10 +17,14 @@ repos: hooks: - id: yamllint args: [--strict, --config-file=.yamllint.yaml] - - repo: https://github.com/koalaman/shellcheck-precommit - rev: 99470f5e12208ff0fb17ab81c3c494f7620a1d8d # v0.11.0 + - repo: local hooks: - id: shellcheck + name: shellcheck + description: Static analysis of shell scripts (mise installed shellcheck) + entry: shellcheck + language: system + types: [shell] - repo: https://github.com/python-jsonschema/check-jsonschema rev: 1a4bb160cab6417b3045e1b37b6b72449243e658 # frozen: 0.37.4 hooks: