Skip to content

ci: align pre-commit hooks and GitHub templates - #16

Closed
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates
Closed

ci: align pre-commit hooks and GitHub templates#16
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates

Conversation

@mc-nv

@mc-nv mc-nv commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

Aligns this repository with the org-wide setup consolidated in triton-inference-server/.github:

  • .pre-commit-config.yaml: shared baseline hooks, conventional-commit message validation (commit-msg stage), and the centralized add-license hook from the org .github repository (rev: v1.4.3 — excludes .github/ templates, never rewrites LICENSE files).
  • Pre-commit CI runs only on files modified by the PR.
  • Caller stub for the org-wide reusable conventional-pr workflow (@v1.4.3): validates the PR title against Conventional Commits (hard gate — it becomes the squash-merge commit), derives one human-readable label per distinct type found in the title and all conforming commit subjects (e.g. ci:CI/CD, feat:feature, fix:fix), enforces org-wide label colors/descriptions, detects cherry-picks, and fails if no type is derivable and no type label is assigned.
  • No per-repo templates: PR templates and issue routing are inherited from the org-wide defaults in triton-inference-server/.github (issues route to the server repository).

Depends on triton-inference-server/.github#5 (pinned tags current: v1.4.3 — already exist, CI is green).

Pros / Cons

Pros

  • Single home (org .github repo) for hooks, templates, issue routing, and the PR-title workflow — one change propagates everywhere.
  • Repos carry only a config file and two small workflow stubs; no template copies to drift.
  • Commit/PR title format enforced both locally (commit-msg hook) and in CI (reusable workflow), with automatic type labels.
  • License hooks never modify LICENSE files.

Cons / risks

  • Version-pinned dependency on the org .github repository (tags are write-once; changes ship as a new tag + rev bump).
  • Template inheritance requires the org .github repository to remain public.

Related Issues / PRs

  • Resolves: TRI-1100

Related PRs:

Test plan

  • pre-commit validate-config passes; pre-commit run --files <PR diff> passes locally with the centralized hooks pinned to the .github branch SHA.
  • After .github#5 merges and v1.4.3 exists: the conventional-pr check validates this PR's own title and applies the ci label.
  • No LICENSE file content is changed by this PR.

Caveats

  • None beyond the merge-order note above.

Checklist

  • PR title follows <commit_type>: <Title> (conventional commit)
  • I ran pre-commit locally on all files changed by this PR and it passes
  • Copyright header is correct on all changed files
  • External contributors: I have read the Contribution guidelines and signed the Contributor License Agreement

Adopt the shared pre-commit baseline: two-line SPDX header, conventional
commit message validation (commit-msg stage), and the centralized
add-license / add-spdx-license hooks from developer_tools v0.2.0.
Run pre-commit CI only on files modified by the PR, and roll out the
standard issue templates and the simplified single PR template.

TRI-1100
@mc-nv mc-nv self-assigned this Jul 18, 2026
This was referenced Jul 18, 2026
Legal's Copyright / License Header Guidance specifies the SPDX form
without a comma after the year.

TRI-1100
@mc-nv
mc-nv marked this pull request as ready for review July 18, 2026 02:05
Human-readable type labels with enforced descriptions and colors.

TRI-1100
@github-actions github-actions Bot added CI/CD Continuous integration and workflow changes (ci: PRs) and removed ci labels Jul 20, 2026
@github-actions github-actions Bot added the chore Maintenance work, no production code change (chore: PRs) label Jul 20, 2026
mc-nv added 3 commits July 21, 2026 08:16
Deliberate maintenance bump to include the year of the current
modifications; required by the add-license hook's new staleness
check (hooks themselves never modify LICENSE files).

TRI-1100
Workflow files are license-processed again (only templates excluded);
refresh the stale copyright year this repo's pre-commit workflow
carried.

TRI-1100
Grant issues:write to the labeling job (review feedback).

TRI-1100
@mc-nv
mc-nv requested a review from pskiran1 July 22, 2026 15:11
@Vinya567

Copy link
Copy Markdown

@greptileai

@greptile-apps

greptile-apps Bot commented Jul 22, 2026

Copy link
Copy Markdown

Greptile Summary

This PR aligns the repository with the org-wide CI/CD baseline in triton-inference-server/.github: it adds a thin caller for the conventional-pr reusable workflow (PR-title linting + auto-labeling) and rewrites the pre-commit workflow to run only on PR-modified files using a null-delimited xargs -0 pipeline, addressing prior space-in-filename and empty-diff concerns.

  • conventional-pr.yml: New caller stub that correctly gates pull_request_target to fork PRs (for writable token) and pull_request to same-repo PRs via an if condition, with permissions scoped to pull-requests: write and issues: write only.
  • pre-commit.yml: Replaces pre-commit/action with a git diff --diff-filter=d HEAD^1 HEAD pipeline; fetch-depth: 2 gives the parent context needed to compute the full PR diff in the GitHub Actions merge-commit checkout model.
  • .pre-commit-config.yaml: Adds default_install_hook_types, a commit-msg-stage conventional-commit hook, the org-wide add-license hook (v1.4.3), and fixes flake8 arg quoting; both org-hook refs are mutually consistent at v1.4.3.

Confidence Score: 5/5

Safe to merge — all changes are CI/tooling configuration with no production code impact.

The changes are well-structured: the pull_request_target security concern is explicitly mitigated by the if guard and by the reusable workflow not checking out PR code; the null-delimited xargs pipeline correctly handles spaces and empty diffs; both org-hook refs are mutually consistent at v1.4.3. The only observation is a minor pinning inconsistency on actions/cache.

No files require special attention; .github/workflows/pre-commit.yml has a minor action-pinning inconsistency noted in comments.

Important Files Changed

Filename Overview
.github/workflows/conventional-pr.yml New caller stub for the org-wide reusable conventional-pr workflow; correctly restricts pull_request_target to fork PRs via an if guard and explicitly scopes permissions to the minimum needed for label management.
.github/workflows/pre-commit.yml Replaces pre-commit/action with a manual run scoped to PR-modified files using null-delimited xargs -0; actions/cache@v4 is pinned to a major version while sibling actions use exact semver (@v5.0.0, @v6.0.0).
.pre-commit-config.yaml Adds default_install_hook_types, conventional-commit message hook (commit-msg stage), and org-wide add-license hook pinned to v1.4.3; fixes flake8 arg quoting; both org-hook revs are mutually consistent.
LICENSE Copyright year bumped from 2023 to 2023-2026; content otherwise unchanged.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    PR([Pull Request opened / updated]) --> EVENT{Event source}

    EVENT -->|same-repo PR| PC_EVENT[pull_request event]
    EVENT -->|fork PR| PT_EVENT[pull_request_target event]

    PC_EVENT --> IF_GUARD{if: head.repo == repository}
    PT_EVENT --> IF_GUARD2{if: head.repo != repository}

    IF_GUARD -->|true| CONV_JOB[conventional-pr job\npermissions: PR write + issues write]
    IF_GUARD2 -->|true| CONV_JOB

    CONV_JOB --> REUSABLE[triton-inference-server/.github\nconventional-pr.yml @ v1.4.3]
    REUSABLE --> LINT[Validate PR title\nConventional Commits]
    REUSABLE --> LABEL[Derive + apply type label\nci / feat / fix / ...]
    REUSABLE --> CHERRY[Detect cherry-picks]

    PR --> PRECOMMIT_JOB[pre-commit job\npermissions: contents read]
    PRECOMMIT_JOB --> CHECKOUT[actions/checkout @ v5.0.0\nfetch-depth: 2]
    CHECKOUT --> CACHE[actions/cache @ v4\n~/.cache/pre-commit]
    CACHE --> DIFF[git diff -z --diff-filter=d HEAD^1 HEAD]
    DIFF --> XARGS[xargs -0 --no-run-if-empty\npre-commit run --files]
    XARGS --> HOOKS[isort · black · flake8\nclang-format · codespell\nconventional-pre-commit\nadd-license @ v1.4.3]

    LOCAL([Developer local commit]) --> COMMIT_MSG[commit-msg hook\nconventional-pre-commit v4.4.0]
    LOCAL --> PRECOMMIT_LOCAL[pre-commit hooks\nall existing hooks]
Loading

Reviews (2): Last reviewed commit: "ci: harden CI workflows and configs per ..." | Re-trigger Greptile

Comment thread .pre-commit-config.yaml Outdated
Comment thread .github/workflows/pre-commit.yml Outdated
- conventional-pr stub: dual pull_request/pull_request_target triggers
  so fork PRs from external contributors get labeled too (the reusable
  workflow never checks out PR code); explicit contents:read; pinned
  v1.4.3.
- pre-commit workflow: robust modified-files runner (null-delimited
  paths, deletion-only PRs handled, deleted paths filtered, no
  undocumented -r flag, cache keyed on config hash).
- flake8 args quoted correctly (the flow-scalar form split at commas
  and silently reduced the select list).
- hooks pinned to .github v1.4.3.

TRI-1100
@mc-nv

mc-nv commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Closing: the team is moving away from centralized org-level configuration in favor of per-repository self-contained setups (see triton-inference-server/server#8897 for the first decentralized implementation). Branch retained for reference. TRI-1100

@mc-nv mc-nv closed this Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance work, no production code change (chore: PRs) CI/CD Continuous integration and workflow changes (ci: PRs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants