Skip to content

ci: run hooks with prek and autofix.ci - #880

Merged
feoh merged 2 commits into
mainfrom
cpatti/prek-autofix
Oct 1, 2026
Merged

feoh merged 2 commits into
mainfrom
cpatti/prek-autofix

Conversation

@feoh

@feoh feoh commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What are the relevant tickets?

Part of mitodl/ol-infrastructure#5805 (standard wave).

Update 2026-10-01: prek is now pinned to 0.5.3, the release before 0.5.4, at the repository owner's request (commit ci: pin prek 0.5.3). Version references below are updated. Any exclude-newer exemption described for prek was removed, because 0.5.3 is outside the window. Green-run links below may point at the earlier 0.5.4 head; the prek check re-ran on the current head.

Description (What does it do?)

Moves this repository's hooks from pre-commit/pre-commit.ci to prek and autofix.ci, following the migration contract and playbook.

  • Adds .github/workflows/autofix.yml from the uv template, running every hook twice as the prek check and handing convergent fixes on PRs to autofix.ci.
  • Replaces pre-commit>=3.0.0 with prek==0.5.3 in a dedicated dependency group included by dev, locked in uv.lock.
  • Adds the interim ci: autofix_prs: false block: pre-commit.ci keeps reporting, but autofix.ci owns fix pushes. App installation membership comes from the migration task and contract, not an independent installation audit.
  • Updates AGENTS.md to use prek, including uv run prek install -f.
Implementation details and migration evidence
  • Workflow. Copied from autofix-uv.yml; main and public checkout already match the template, and no additional toolchains are needed. The committed yamlfmt rewrite parses identically to the original template, including all shared steps. Permissions remain contents: read, with no secrets. CI installs only the locked prek group. Template tests: 62 pass, with only the expected test_this_repository_runs_the_uv_template failure, which checks ol-github-workflows' own workflow.
  • Lockfile. Relocked with uv 0.12.20. Only the root dev/prek groups, prek 0.5.3, and removal of pre-commit and its exclusive dependencies change; all other packages remain identical. There is no exclude-newer setting to exempt. The unchanged uv-lock hook at 0.12.17 leaves this output stable on consecutive runs.
  • Old ci: skip hooks: none; there was no ci: block. All 17 configured hooks now run in the added workflow.
  • Contract D4 drift: no existing tracked files needed drift fixes. yamlfmt reformatted only the new workflow, committed locally because autofix.ci refuses fixes under .github/. No hook was narrowed.
  • Contract §2 item 1 exceptions: none. Parsed hook configuration is identical apart from the interim ci: block.
  • Renovate. renovate.json extends local>mitodl/.github:renovate-config; the fetched org preset explicitly enables the pre-commit manager and extends config:best-practices. Hook revisions, action digests, and the locked prek pin stay covered.
  • CODEOWNERS: no file exists. Adding the first workflow owner remains a separate fleet decision, as in the pilots.

Seeded checks used staged scratch files, running each hook with --all-files, then removed every seed and verified the intended diff was preserved:

Hook Seed Result
trailing-whitespace trailing spaces Reported/fixed, exit 1
end-of-file-fixer missing final newline Reported/fixed, exit 1
check-yaml unterminated sequence Reported, exit 1
check-added-large-files 600 KiB scratch file Reported, exit 1
check-merge-conflict conflict markers Passed silently, exit 0; finding below
check-toml unterminated array Reported, exit 1
debug-statements breakpoint() Reported, exit 1
yamlfmt flow-style mapping Reported/fixed, exit 1
yamllint duplicate mapping key Reported, exit 1
detect-secrets synthetic high-entropy password Reported, exit 1
ruff-format unformatted assignment Reported/fixed, exit 1
ruff undefined name Reported, exit 1
mypy string assigned to annotated integer Reported, exit 1
rstcheck unknown directive Reported, exit 1
actionlint undefined expression context Reported, exit 1
zizmor unpinned checkout action Reported, prek exit 1
uv-lock stale prek specifier in generated lock metadata Regenerated original output, exit 1
  • FINDING: check-merge-conflict does not report conflict markers outside an active merge. Its source returns early unless a merge is in progress or --assume-in-merge is set; this config has no such argument. Existing behavior is intentionally unchanged in this migration.
  • Generated-file probe: adding a comment alone to uv.lock was not enough to trigger regeneration (exit 0). A stale dependency specifier did trigger regeneration and restored the exact original lockfile. This is a generator, not a code linter.

How can this be tested?

uv sync
uv run prek install -f
uv run prek run --all-files
uv run prek run --all-files
  • All 17 hooks passed twice consecutively after staging the intended changes; neither pass changed files.
  • The CI-only install (uv sync --frozen --only-group prek, uv 0.12.20) also left the committed tree clean; both direct prek passes succeeded without the project environment.
  • uvx zizmor@1.30.1 --offline .github/workflows/autofix.yml: no findings.
  • gitleaks git --log-opts="origin/main..HEAD": one commit scanned, no leaks.

Green prek run on PR head 187166d5001415f41861b58ecaabf2493963014f: successful job, 49 seconds. Both passes succeeded; autofix.ci reported "Nothing to do!" and no autofix-ci[bot] commit landed. Other completed checks passed; integration-tests (master) remained in progress after the 20-minute watch window.

Additional Context

  • GitHub's effective main-branch rules returned no required status-check contexts. This PR does not change required checks.
  • After merge, follow contract §6: sample at least 20 eligible merged PRs (or obtain the owner's low-traffic sign-off), declare prek in ol-infrastructure, and run the blocked-PR check. Then an org owner deselects this repository from pre-commit.ci installation 22207049 and a cleanup PR removes the interim ci: block.
  • Rollback follows contract §9: remove the required context first if added; remove the interim block and delete the workflow in a new PR, not a revert; restore pre-commit.ci installation membership if needed; remove autofix.ci installation membership.

Pin prek 0.5.4 in a dedicated dependency group included by dev, and
copy the uv autofix.ci workflow with its locally formatted YAML.
Keep all 17 hooks unchanged and disable pre-commit.ci fix pushes
until the post-merge cutover. Document prek install -f in AGENTS.md.

Part of mitodl/ol-infrastructure#5805
Copilot AI balanced review requested due to automatic review settings October 1, 2026 01:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The migration matches the shared template and contract, preserves existing hooks, and the new workflow completed successfully.

Review effort: Balanced
Findings: None

What changed in this PR

Migrates repository hook execution from pre-commit.ci to prek and autofix.ci according to the shared migration contract.

Changes:

  • Adds the autofix.ci workflow with two-pass prek validation.
  • Pins prek in a dedicated dependency group and updates the lockfile.
  • Updates hook configuration and contributor guidance for prek.
File Description
.github/​workflows/​autofix.yml Adds prek and autofix.ci automation.
.pre-commit-config.yaml Disables pre-commit.ci fix pushes during migration.
pyproject.toml Replaces pre-commit with pinned prek dependency.
uv.lock Locks prek and removes obsolete pre-commit dependencies.
AGENTS.md Documents prek installation and usage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Downgrade prek from 0.5.4 to the previous release, 0.5.3 (2026-09-13), at
the repository owner's request. Where the uv project exempted prek from
exclude-newer, drop that exemption: it existed only so uv could resolve
0.5.4, and 0.5.3 is outside the window.

Part of mitodl/ol-infrastructure#5805
@feoh
feoh merged commit 50483d3 into main Oct 1, 2026
14 checks passed
@feoh
feoh deleted the cpatti/prek-autofix branch October 1, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants