From a630d4e210e7001f18a408d622c744d8f8879540 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 10:31:35 +0100 Subject: [PATCH 1/8] feat: configure git to use GITHUB_TOKEN for authentication in update process --- .../workflows/auto-update-precommit-hooks.yml | 26 ++++++++++++------- 1 file changed, 17 insertions(+), 9 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index 0863d4a..b6724ed 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -588,7 +588,7 @@ jobs: with open('configs/precommit-update-tracking.json', 'r') as f: tracking = json.load(f) except FileNotFoundError: - tracking = {'last_updated': datetime.utcnow().isoformat() + 'Z', 'hooks': {}} + tracking = {'last_updated': datetime.now(timezone.utc).isoformat() + 'Z', 'hooks': {}} # Create a mapping of repo URLs to new SHAs update_map = {update['repo']: update for update in release_info} @@ -606,9 +606,9 @@ jobs: 'current_sha': update['new_sha'], 'current_version': update['new_version'], 'semver_levels': { - 'major': datetime.utcnow().isoformat() + 'Z', - 'minor': datetime.utcnow().isoformat() + 'Z', - 'patch': datetime.utcnow().isoformat() + 'Z' + 'major': datetime.now(timezone.utc).isoformat() + 'Z', + 'minor': datetime.now(timezone.utc).isoformat() + 'Z', + 'patch': datetime.now(timezone.utc).isoformat() + 'Z' } } else: @@ -616,9 +616,9 @@ jobs: tracking['hooks'][repo_url]['current_sha'] = update['new_sha'] tracking['hooks'][repo_url]['current_version'] = update['new_version'] if semver != 'unknown': - tracking['hooks'][repo_url]['semver_levels'][semver] = datetime.utcnow().isoformat() + 'Z' + tracking['hooks'][repo_url]['semver_levels'][semver] = datetime.now(timezone.utc).isoformat() + 'Z' - tracking['hooks'][repo_url]['last_updated'] = datetime.utcnow().isoformat() + 'Z' + tracking['hooks'][repo_url]['last_updated'] = datetime.now(timezone.utc).isoformat() + 'Z' # Write updated files with open('.pre-commit-config.yaml', 'w') as f: @@ -743,18 +743,26 @@ jobs: pr_body = generate_pr_body(release_info, skipped, cooldown_config) # Create branch and commit - branch_name = f"chore/precommit-updates-{datetime.utcnow().strftime('%Y%m%d')}" + branch_name = f"chore/precommit-updates-{datetime.now(timezone.utc).strftime('%Y%m%d')}" subprocess.run(['git', 'config', 'user.name', 'github-actions[bot]'], check=True) subprocess.run(['git', 'config', 'user.email', '41898282+github-actions[bot]@users.noreply.github.com'], check=True) + + # Configure git to use GITHUB_TOKEN for authentication (secure alternative to persist-credentials) + github_token = os.environ.get('GITHUB_TOKEN', '') + subprocess.run( + ['git', 'config', '--global', 'url.https://x-access-token:' + github_token + '@github.com/.insteadOf', 'https://github.com/'], + check=True + ) + subprocess.run(['git', 'checkout', '-b', branch_name], check=True) subprocess.run(['git', 'add', '.pre-commit-config.yaml', 'configs/precommit-update-tracking.json'], check=True) commit_msg = f"chore(pre-commit): auto-update hooks\n\nUpdated {len(release_info)} pre-commit hook(s)" subprocess.run(['git', 'commit', '-m', commit_msg], check=True) - # Push branch - subprocess.run(['git', 'push', '-u', 'origin', branch_name], check=True, env={**os.environ, 'GIT_TRACE': '1'}) + # Push branch (git authentication already configured via credential helper) + subprocess.run(['git', 'push', '-u', 'origin', branch_name], check=True) # Create PR using GitHub CLI pr_result = subprocess.run( From 7436743120bd5fe5e0d559f454ce509fe76bb9c9 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 10:42:41 +0100 Subject: [PATCH 2/8] feat: update git push command to use --force-with-lease for safer branch updates --- .github/workflows/auto-update-precommit-hooks.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index b6724ed..325cf5f 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -761,8 +761,9 @@ jobs: commit_msg = f"chore(pre-commit): auto-update hooks\n\nUpdated {len(release_info)} pre-commit hook(s)" subprocess.run(['git', 'commit', '-m', commit_msg], check=True) - # Push branch (git authentication already configured via credential helper) - subprocess.run(['git', 'push', '-u', 'origin', branch_name], check=True) + # Push branch with force-with-lease to handle existing remote branch safely + # (useful when multiple runs occur on the same day during testing) + subprocess.run(['git', 'push', '--force-with-lease', '-u', 'origin', branch_name], check=True) # Create PR using GitHub CLI pr_result = subprocess.run( From 08da0d1a9d345af5076d62d25dedfc169cb73990 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 10:45:17 +0100 Subject: [PATCH 3/8] feat: update setup-python action to version 7.0.0 for improved functionality --- .github/workflows/auto-update-precommit-hooks.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index 325cf5f..3a87c2a 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -83,7 +83,7 @@ jobs: persist-credentials: false - name: Set up Python - uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c # v5.0.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.11" @@ -312,7 +312,7 @@ jobs: persist-credentials: false - name: Set up Python - uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c # v5.0.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.11" @@ -421,7 +421,7 @@ jobs: persist-credentials: false - name: Set up Python - uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c # v5.0.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.11" @@ -539,7 +539,7 @@ jobs: persist-credentials: false - name: Set up Python - uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c # v5.0.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.11" From c2c03f5f4fac430be452c6c1228da0fe7b0eac0a Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 10:46:10 +0100 Subject: [PATCH 4/8] feat: update git configuration to use GITHUB_TOKEN via HTTP header for improved reliability --- .github/workflows/auto-update-precommit-hooks.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index 3a87c2a..3d9c5b4 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -748,10 +748,11 @@ jobs: subprocess.run(['git', 'config', 'user.name', 'github-actions[bot]'], check=True) subprocess.run(['git', 'config', 'user.email', '41898282+github-actions[bot]@users.noreply.github.com'], check=True) - # Configure git to use GITHUB_TOKEN for authentication (secure alternative to persist-credentials) + # Configure git to use GITHUB_TOKEN for authentication via HTTP header + # This is more reliable than URL rewriting in GitHub Actions environments github_token = os.environ.get('GITHUB_TOKEN', '') subprocess.run( - ['git', 'config', '--global', 'url.https://x-access-token:' + github_token + '@github.com/.insteadOf', 'https://github.com/'], + ['git', 'config', '--global', 'http.extraheader', f'Authorization: token {github_token}'], check=True ) From 60e4e3c17c5351d547f3cd840504c925e9a9cd94 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 10:49:23 +0100 Subject: [PATCH 5/8] feat: update git push command to use token in URL for improved security --- .../workflows/auto-update-precommit-hooks.yml | 22 +++++++++---------- 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index 3d9c5b4..1811d85 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -747,24 +747,22 @@ jobs: subprocess.run(['git', 'config', 'user.name', 'github-actions[bot]'], check=True) subprocess.run(['git', 'config', 'user.email', '41898282+github-actions[bot]@users.noreply.github.com'], check=True) - - # Configure git to use GITHUB_TOKEN for authentication via HTTP header - # This is more reliable than URL rewriting in GitHub Actions environments - github_token = os.environ.get('GITHUB_TOKEN', '') - subprocess.run( - ['git', 'config', '--global', 'http.extraheader', f'Authorization: token {github_token}'], - check=True - ) - subprocess.run(['git', 'checkout', '-b', branch_name], check=True) subprocess.run(['git', 'add', '.pre-commit-config.yaml', 'configs/precommit-update-tracking.json'], check=True) commit_msg = f"chore(pre-commit): auto-update hooks\n\nUpdated {len(release_info)} pre-commit hook(s)" subprocess.run(['git', 'commit', '-m', commit_msg], check=True) - # Push branch with force-with-lease to handle existing remote branch safely - # (useful when multiple runs occur on the same day during testing) - subprocess.run(['git', 'push', '--force-with-lease', '-u', 'origin', branch_name], check=True) + # Push branch using token in URL (temporary, safe because token is already exposed via env) + # Get repository info from environment + repo = os.environ.get('GITHUB_REPOSITORY', '') + github_token = os.environ.get('GITHUB_TOKEN', '') + remote_url = f'https://x-access-token:{github_token}@github.com/{repo}.git' + subprocess.run( + ['git', 'push', '--force-with-lease', '-u', remote_url, branch_name], + check=True, + env={**os.environ, 'GIT_TRACE': '0'} # Disable tracing to avoid logging token + ) # Create PR using GitHub CLI pr_result = subprocess.run( From eb4e22bfe3950eabd17866b5c6ec021dc23b8608 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 11:51:34 +0100 Subject: [PATCH 6/8] feat: update push command to use GitHub CLI for authentication and simplify remote URL handling --- .github/workflows/auto-update-precommit-hooks.yml | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index 1811d85..c79ed39 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -753,15 +753,14 @@ jobs: commit_msg = f"chore(pre-commit): auto-update hooks\n\nUpdated {len(release_info)} pre-commit hook(s)" subprocess.run(['git', 'commit', '-m', commit_msg], check=True) - # Push branch using token in URL (temporary, safe because token is already exposed via env) - # Get repository info from environment - repo = os.environ.get('GITHUB_REPOSITORY', '') - github_token = os.environ.get('GITHUB_TOKEN', '') - remote_url = f'https://x-access-token:{github_token}@github.com/{repo}.git' + # Use GitHub CLI to authenticate git for pushing + # gh auth setup-git configures git to use gh's stored credentials + subprocess.run(['gh', 'auth', 'setup-git'], check=True) + + # Push branch subprocess.run( - ['git', 'push', '--force-with-lease', '-u', remote_url, branch_name], - check=True, - env={**os.environ, 'GIT_TRACE': '0'} # Disable tracing to avoid logging token + ['git', 'push', '--force-with-lease', '-u', 'origin', branch_name], + check=True ) # Create PR using GitHub CLI From 05385b3cc7ee00eb76288912fa99ab6e3a82e0e3 Mon Sep 17 00:00:00 2001 From: Colin Daglish Date: Thu, 10 Sep 2026 11:59:23 +0100 Subject: [PATCH 7/8] feat: refine update detection to only track semantic versioned releases and skip repos without tagged releases --- .../workflows/auto-update-precommit-hooks.yml | 42 +++---------------- 1 file changed, 5 insertions(+), 37 deletions(-) diff --git a/.github/workflows/auto-update-precommit-hooks.yml b/.github/workflows/auto-update-precommit-hooks.yml index c79ed39..fc12291 100644 --- a/.github/workflows/auto-update-precommit-hooks.yml +++ b/.github/workflows/auto-update-precommit-hooks.yml @@ -142,29 +142,6 @@ jobs: return None - def get_latest_commit_sha(repo_url: str, branch: str = 'HEAD') -> Optional[str]: - """Fetch latest commit SHA from a repository.""" - try: - match = re.search(r'github\.com/([^/]+)/(.+?)(?:\.git)?$', repo_url) - if not match: - return None - - owner, repo = match.groups() - - cmd = [ - 'gh', 'api', '--paginate', - f'repos/{owner}/{repo}/commits', - '-q', '.[0].sha' - ] - - result = subprocess.run(cmd, capture_output=True, text=True, timeout=10) - if result.returncode == 0 and result.stdout.strip(): - return result.stdout.strip() - except Exception as e: - print(f"Warning: Error fetching latest commit for {repo_url}: {e}") - - return None - def resolve_sha_to_tag(repo_url: str, sha: str) -> Optional[str]: """Resolve a commit SHA to its tag, if one exists.""" try: @@ -236,7 +213,8 @@ jobs: print(f"Checking updates for: {repo_url}") - # Try to get latest release first + # Only check tagged releases (Dependabot behavior) + # Skips repositories without semantic versioning release_info = get_latest_release(repo_url) if release_info: @@ -268,19 +246,9 @@ jobs: }) print(f" Update available: {old_version} -> {latest_tag}") else: - # Fall back to latest commit if no releases - latest_sha = get_latest_commit_sha(repo_url) - if latest_sha and latest_sha != current_sha: - print(f" Update available (commit): {current_sha[:7]} -> {latest_sha[:7]}") - updates.append({ - 'repo': repo_url, - 'old_sha': current_sha, - 'new_sha': latest_sha, - 'old_version': current_sha[:7], - 'new_version': latest_sha[:7], - 'semver_level': 'patch', # Default to patch for commits - 'commit_range': f'{current_sha}...{latest_sha}' - }) + # No tagged releases found - skip this repo (Dependabot-aligned behavior) + # This ensures we only track semantic versioned hooks + print(f" ⊘ Skipped: No tagged releases found (only tagged versions are tracked, like Dependabot)") # Output results if updates: From 98baa5530e5539367123324f6549a2eb276b53ed Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Thu, 10 Sep 2026 11:02:34 +0000 Subject: [PATCH 8/8] chore(pre-commit): auto-update hooks Updated 2 pre-commit hook(s) --- .pre-commit-config.yaml | 23 +++++++++++++---------- configs/precommit-update-tracking.json | 16 ++++++++-------- 2 files changed, 21 insertions(+), 18 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index eb454fb..6018309 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,11 +1,14 @@ repos: - - repo: https://github.com/zizmorcore/zizmor-pre-commit - rev: 451b56af716f9f0d0c2b816503a3fd0cf8b036fa # frozen: v1.29.0 - hooks: - - id: zizmor - args: [--fix, --persona=pedantic] - - repo: https://github.com/compilerla/conventional-pre-commit - rev: 3db014c16a9d31997ab8c07a4d61fcce936c8f0d # frozen: v4.4.0 - hooks: - - id: conventional-pre-commit - stages: [commit-msg] \ No newline at end of file +- repo: https://github.com/zizmorcore/zizmor-pre-commit + rev: fa412071e4f5d44d44f9e365f4676f9df92456a2 + hooks: + - id: zizmor + args: + - --fix + - --persona=pedantic +- repo: https://github.com/compilerla/conventional-pre-commit + rev: 91ab4bf57e58b32adf1a122681f6ebe164d081c8 + hooks: + - id: conventional-pre-commit + stages: + - commit-msg diff --git a/configs/precommit-update-tracking.json b/configs/precommit-update-tracking.json index 6cb4bfd..315cec1 100644 --- a/configs/precommit-update-tracking.json +++ b/configs/precommit-update-tracking.json @@ -2,24 +2,24 @@ "last_updated": "2026-09-10T00:00:00Z", "hooks": { "https://github.com/zizmorcore/zizmor-pre-commit": { - "last_updated": "2026-09-10T00:00:00Z", - "current_sha": "451b56af716f9f0d0c2b816503a3fd0cf8b036fa", - "current_version": "v1.29.0", + "last_updated": "2026-09-10T11:02:34.747610+00:00Z", + "current_sha": "fa412071e4f5d44d44f9e365f4676f9df92456a2", + "current_version": "v1.30.1", "semver_levels": { "major": "2026-09-10T00:00:00Z", - "minor": "2026-09-10T00:00:00Z", + "minor": "2026-09-10T11:02:34.747601+00:00Z", "patch": "2026-09-10T00:00:00Z" } }, "https://github.com/compilerla/conventional-pre-commit": { - "last_updated": "2026-09-10T00:00:00Z", - "current_sha": "3db014c16a9d31997ab8c07a4d61fcce936c8f0d", + "last_updated": "2026-09-10T11:02:34.747616+00:00Z", + "current_sha": "91ab4bf57e58b32adf1a122681f6ebe164d081c8", "current_version": "v4.4.0", "semver_levels": { "major": "2026-09-10T00:00:00Z", "minor": "2026-09-10T00:00:00Z", - "patch": "2026-09-10T00:00:00Z" + "patch": "2026-09-10T11:02:34.747614+00:00Z" } } } -} +} \ No newline at end of file