ci: run hooks with prek and autofix.ci - #880
Merged
Merged
Conversation
Pin prek 0.5.4 in a dedicated dependency group included by dev, and copy the uv autofix.ci workflow with its locally formatted YAML. Keep all 17 hooks unchanged and disable pre-commit.ci fix pushes until the post-merge cutover. Document prek install -f in AGENTS.md. Part of mitodl/ol-infrastructure#5805
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The migration matches the shared template and contract, preserves existing hooks, and the new workflow completed successfully.
Review effort: Balanced
Findings: None
What changed in this PR
Migrates repository hook execution from pre-commit.ci to prek and autofix.ci according to the shared migration contract.
Changes:
- Adds the autofix.ci workflow with two-pass prek validation.
- Pins prek in a dedicated dependency group and updates the lockfile.
- Updates hook configuration and contributor guidance for prek.
| File | Description |
|---|---|
.github/workflows/autofix.yml |
Adds prek and autofix.ci automation. |
.pre-commit-config.yaml |
Disables pre-commit.ci fix pushes during migration. |
pyproject.toml |
Replaces pre-commit with pinned prek dependency. |
uv.lock |
Locks prek and removes obsolete pre-commit dependencies. |
AGENTS.md |
Documents prek installation and usage. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Downgrade prek from 0.5.4 to the previous release, 0.5.3 (2026-09-13), at the repository owner's request. Where the uv project exempted prek from exclude-newer, drop that exemption: it existed only so uv could resolve 0.5.4, and 0.5.3 is outside the window. Part of mitodl/ol-infrastructure#5805
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are the relevant tickets?
Part of mitodl/ol-infrastructure#5805 (standard wave).
Description (What does it do?)
Moves this repository's hooks from pre-commit/pre-commit.ci to prek and autofix.ci, following the migration contract and playbook.
.github/workflows/autofix.ymlfrom the uv template, running every hook twice as theprekcheck and handing convergent fixes on PRs to autofix.ci.pre-commit>=3.0.0withprek==0.5.3in a dedicated dependency group included bydev, locked inuv.lock.ci: autofix_prs: falseblock: pre-commit.ci keeps reporting, but autofix.ci owns fix pushes. App installation membership comes from the migration task and contract, not an independent installation audit.AGENTS.mdto use prek, includinguv run prek install -f.Implementation details and migration evidence
autofix-uv.yml;mainand public checkout already match the template, and no additional toolchains are needed. The committed yamlfmt rewrite parses identically to the original template, including all shared steps. Permissions remaincontents: read, with no secrets. CI installs only the lockedprekgroup. Template tests: 62 pass, with only the expectedtest_this_repository_runs_the_uv_templatefailure, which checks ol-github-workflows' own workflow.exclude-newersetting to exempt. The unchangeduv-lockhook at 0.12.17 leaves this output stable on consecutive runs.ci: skiphooks: none; there was noci:block. All 17 configured hooks now run in the added workflow..github/. No hook was narrowed.ci:block.renovate.jsonextendslocal>mitodl/.github:renovate-config; the fetched org preset explicitly enables thepre-commitmanager and extendsconfig:best-practices. Hook revisions, action digests, and the locked prek pin stay covered.Seeded checks used staged scratch files, running each hook with
--all-files, then removed every seed and verified the intended diff was preserved:breakpoint()check-merge-conflictdoes not report conflict markers outside an active merge. Its source returns early unless a merge is in progress or--assume-in-mergeis set; this config has no such argument. Existing behavior is intentionally unchanged in this migration.uv.lockwas not enough to trigger regeneration (exit 0). A stale dependency specifier did trigger regeneration and restored the exact original lockfile. This is a generator, not a code linter.How can this be tested?
uv sync --frozen --only-group prek, uv 0.12.20) also left the committed tree clean; both direct prek passes succeeded without the project environment.uvx zizmor@1.30.1 --offline .github/workflows/autofix.yml: no findings.gitleaks git --log-opts="origin/main..HEAD": one commit scanned, no leaks.Green
prekrun on PR head187166d5001415f41861b58ecaabf2493963014f: successful job, 49 seconds. Both passes succeeded; autofix.ci reported "Nothing to do!" and no autofix-ci[bot] commit landed. Other completed checks passed;integration-tests (master)remained in progress after the 20-minute watch window.Additional Context
prekin ol-infrastructure, and run the blocked-PR check. Then an org owner deselects this repository from pre-commit.ci installation 22207049 and a cleanup PR removes the interimci:block.