Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ repos:
# Repo hygiene — fast, language-agnostic sanity checks.
# ---------------------------------------------------------------------------
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v5.0.0
rev: v6.0.0
hooks:
- id: trailing-whitespace
# Markdown trailing whitespace is meaningful (two spaces = hard break).
Expand Down Expand Up @@ -88,9 +88,10 @@ repos:
# Conventional Commits — enforced on the commit message (commit-msg hook).
# ---------------------------------------------------------------------------
- repo: https://github.com/compilerla/conventional-pre-commit
rev: v3.6.0
rev: v4.4.0
hooks:
- id: conventional-pre-commit
args: ["--strict"]
stages: [commit-msg]

# ---------------------------------------------------------------------------
Expand Down
5 changes: 5 additions & 0 deletions docs/06-field-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -448,6 +448,11 @@ Base: `~/.vscode-server/data/User/`
Pre-commit-**only** hosted hooks (gitleaks, markdownlint-cli2, conventional-pre-commit,
pre-commit-hooks) have a single pin so they don't drift, but Dependabot can't bump them either —
they only move via `pre-commit autoupdate`.
- **Hook major update, 2026-09-30:** `pre-commit-hooks` v6 requires Python >=3.9 (CI uses 3.12);
`conventional-pre-commit` v4 permits merge/fixup messages by default, so pass `--strict` to
preserve the previous rejection behavior. Test both valid and rejected commit messages.
`pre-commit autoupdate` uses `git describe` on upstream HEAD rather than the highest tag;
gitleaks v8.30.1 is tagged off master, so review its proposed v8.30.0 downgrade manually.
- **Edit-tool unicode trap.** The string-replace edit tools can write `\uXXXX` escapes as **literal
text**. Use the actual glyphs (em-dash —, middot ·, arrow →, section §) in the replacement, or a
Python heredoc with ASCII anchors for unicode-heavy edits.
Expand Down
Loading