Skip to content

ci: align pre-commit hooks and GitHub templates#158

Closed
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates
Closed

ci: align pre-commit hooks and GitHub templates#158
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates

Conversation

@mc-nv

@mc-nv mc-nv commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

Aligns this repository with the org-wide setup consolidated in triton-inference-server/.github:

  • .pre-commit-config.yaml: shared baseline hooks, conventional-commit message validation (commit-msg stage), and the centralized add-license hook from the org .github repository (rev: v1.4.3 — excludes .github/ templates, never rewrites LICENSE files).
  • Pre-commit CI runs only on files modified by the PR.
  • Caller stub for the org-wide reusable conventional-pr workflow (@v1.4.3): validates the PR title against Conventional Commits (hard gate — it becomes the squash-merge commit), derives one human-readable label per distinct type found in the title and all conforming commit subjects (e.g. ci:CI/CD, feat:feature, fix:fix), enforces org-wide label colors/descriptions, detects cherry-picks, and fails if no type is derivable and no type label is assigned.
  • No per-repo templates: PR templates and issue routing are inherited from the org-wide defaults in triton-inference-server/.github (issues route to the server repository).

Repo-specific: the workflow file is renamed pre-commit.yaml → pre-commit.yml.

Depends on triton-inference-server/.github#5 (pinned tags current: v1.4.3 — already exist, CI is green).

Pros / Cons

Pros

  • Single home (org .github repo) for hooks, templates, issue routing, and the PR-title workflow — one change propagates everywhere.
  • Repos carry only a config file and two small workflow stubs; no template copies to drift.
  • Commit/PR title format enforced both locally (commit-msg hook) and in CI (reusable workflow), with automatic type labels.
  • License hooks never modify LICENSE files.

Cons / risks

  • Version-pinned dependency on the org .github repository (tags are write-once; changes ship as a new tag + rev bump).
  • Template inheritance requires the org .github repository to remain public.

Related Issues / PRs

  • Resolves: TRI-1100

Related PRs:

Test plan

  • pre-commit validate-config passes; pre-commit run --files <PR diff> passes locally with the centralized hooks pinned to the .github branch SHA.
  • After .github#5 merges and v1.4.3 exists: the conventional-pr check validates this PR's own title and applies the ci label.
  • No LICENSE file content is changed by this PR.

Caveats

  • None beyond the merge-order note above.

Checklist

  • PR title follows <commit_type>: <Title> (conventional commit)
  • I ran pre-commit locally on all files changed by this PR and it passes
  • Copyright header is correct on all changed files
  • External contributors: I have read the Contribution guidelines and signed the Contributor License Agreement

Adopt the shared pre-commit baseline: two-line SPDX header, conventional
commit message validation (commit-msg stage), and the centralized
add-license / add-spdx-license hooks from developer_tools v0.2.0.
Run pre-commit CI only on files modified by the PR, and roll out the
standard issue templates and the simplified single PR template.

TRI-1100
@mc-nv mc-nv self-assigned this Jul 18, 2026
This was referenced Jul 18, 2026
Legal's Copyright / License Header Guidance specifies the SPDX form
without a comma after the year.

TRI-1100
@mc-nv
mc-nv marked this pull request as ready for review July 18, 2026 02:05
Human-readable type labels with enforced descriptions and colors.

TRI-1100
@github-actions github-actions Bot added CI/CD Continuous integration and workflow changes (ci: PRs) and removed ci labels Jul 20, 2026
@github-actions github-actions Bot added the chore Maintenance work, no production code change (chore: PRs) label Jul 20, 2026
mc-nv added 3 commits July 21, 2026 08:16
The add-license hook now fails when the LICENSE copyright year is
stale.

TRI-1100
Workflow files are license-processed again (only templates excluded);
refresh the stale copyright year this repo's pre-commit workflow
carried.

TRI-1100
Grant issues:write to the labeling job (review feedback).

TRI-1100
@mc-nv
mc-nv requested a review from pskiran1 July 22, 2026 15:12
@Vinya567

Copy link
Copy Markdown

@greptileai

@greptile-apps

greptile-apps Bot commented Jul 22, 2026

Copy link
Copy Markdown

Greptile Summary

This PR aligns the repository's CI and pre-commit setup with the org-wide configuration in triton-inference-server/.github, replacing per-repo copies with thin callers pinned to v1.4.3.

  • conventional-pr.yml: New workflow stub that routes same-repo and fork PRs to the correct GitHub event (pull_request vs pull_request_target), then delegates to the org reusable workflow for PR-title validation and automatic type labeling.
  • pre-commit.yml: Renamed, modernized action pins, added contents: read permission, and replaced the fragile manual file-list step with a null-delimited xargs pipeline that correctly handles spaces and deleted files.
  • .pre-commit-config.yaml: Adds the commit-msg stage with conventional-pre-commit, fixes flake8 arg quoting, switches add-license to the .github hook repo, and documents the existing Helm-template exclusion.

Confidence Score: 5/5

Safe to merge — changes are limited to CI workflow stubs and hook configuration, with no production code affected.

All three files introduce or update CI/pre-commit infrastructure only. The pull_request_target usage is guarded by a correct if condition and the reusable workflow is version-pinned, keeping the attack surface bounded. The previously flagged missing contents: read permission has been added. No logic-bearing code is changed.

No files require special attention beyond the already-threaded check-yaml exclusion scope in .pre-commit-config.yaml.

Important Files Changed

Filename Overview
.github/workflows/conventional-pr.yml New workflow — thin caller for the org-wide reusable conventional-pr workflow. Correctly gates same-repo vs. fork PRs via the if condition, and now includes contents: read (addressing the previous review comment). Pinned to v1.4.3.
.github/workflows/pre-commit.yml Renamed from .yaml, upgraded action pins, added contents: read, and replaced the manual modified_files step with a null-delimited xargs pipeline that correctly filters deleted files and handles paths with spaces.
.pre-commit-config.yaml Adds commit-msg stage and conventional-pre-commit hook, fixes flake8 arg quoting, updates add-license source to .github at v1.4.3, and adds an explanatory comment for the Helm-template check-yaml exclusion (exclusion scope remains broad — flagged in a prior review thread).

Sequence Diagram

sequenceDiagram
    participant Dev as Developer
    participant GH as GitHub
    participant CPR as conventional-pr.yml (caller)
    participant OrgWF as org .github/conventional-pr.yml@v1.4.3
    participant PC as pre-commit.yml
    participant OrgHook as .github repo hooks (add-license, v1.4.3)

    Dev->>GH: Open / update PR
    GH->>CPR: Trigger pull_request (same-repo) OR pull_request_target (fork)
    CPR->>CPR: if condition: only one event path fires
    CPR->>OrgWF: uses: reusable workflow (permissions: PR write, issues write, contents read)
    OrgWF->>GH: Validate PR title (Conventional Commits)
    OrgWF->>GH: Derive and apply type label (ci, feat, fix, ...)
    OrgWF->>GH: Detect cherry-picks via git history API

    Dev->>GH: Push commits to PR branch
    GH->>PC: Trigger pull_request event
    PC->>PC: checkout (fetch-depth 2), setup-python, restore cache
    PC->>PC: pip install pre-commit
    PC->>PC: "git diff --name-only -z --diff-filter=d HEAD^1 HEAD | xargs -0 pre-commit --files"
    PC->>OrgHook: add-license hook (via .pre-commit-config.yaml rev v1.4.3)
    PC->>GH: Report pass/fail

    Dev->>Dev: git commit (local)
    Note over Dev: commit-msg hook fires (conventional-pre-commit v4.4.0)
    Dev->>Dev: Validate message format before commit succeeds
Loading

Reviews (2): Last reviewed commit: "ci: harden CI workflows and configs per ..." | Re-trigger Greptile

Comment thread .pre-commit-config.yaml
Comment thread .github/workflows/conventional-pr.yml Outdated
Comment thread .github/workflows/conventional-pr.yml Outdated
- conventional-pr stub: dual pull_request/pull_request_target triggers
  so fork PRs from external contributors get labeled too (the reusable
  workflow never checks out PR code); explicit contents:read; pinned
  v1.4.3.
- pre-commit workflow: robust modified-files runner (null-delimited
  paths, deletion-only PRs handled, deleted paths filtered, no
  undocumented -r flag, cache keyed on config hash).
- flake8 args quoted correctly (the flow-scalar form split at commas
  and silently reduced the select list).
- hooks pinned to .github v1.4.3.

TRI-1100
@mc-nv

mc-nv commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Closing: the team is moving away from centralized org-level configuration in favor of per-repository self-contained setups (see triton-inference-server/server#8897 for the first decentralized implementation). Branch retained for reference. TRI-1100

@mc-nv mc-nv closed this Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance work, no production code change (chore: PRs) CI/CD Continuous integration and workflow changes (ci: PRs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants