Skip to content

ci: align pre-commit hooks and GitHub templates - #133

Closed
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates
Closed

ci: align pre-commit hooks and GitHub templates#133
mc-nv wants to merge 17 commits into
mainfrom
mchornyi/TRI-1100/github-align-hooks-and-templates

Conversation

@mc-nv

@mc-nv mc-nv commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

Aligns this repository with the org-wide setup consolidated in triton-inference-server/.github:

  • .pre-commit-config.yaml: shared baseline hooks, conventional-commit message validation (commit-msg stage), and the centralized add-license hook from the org .github repository (rev: v1.4.3 — excludes .github/ templates, never rewrites LICENSE files).
  • Pre-commit CI runs only on files modified by the PR.
  • Caller stub for the org-wide reusable conventional-pr workflow (@v1.4.3): validates the PR title against Conventional Commits (hard gate — it becomes the squash-merge commit), derives one human-readable label per distinct type found in the title and all conforming commit subjects (e.g. ci:CI/CD, feat:feature, fix:fix), enforces org-wide label colors/descriptions, detects cherry-picks, and fails if no type is derivable and no type label is assigned.
  • No per-repo templates: PR templates and issue routing are inherited from the org-wide defaults in triton-inference-server/.github (issues route to the server repository).

Repo-specific: keeps the deploy/templates check-yaml exclude.

Depends on triton-inference-server/.github#5 (pinned tags current: v1.4.3 — already exist, CI is green).

Pros / Cons

Pros

  • Single home (org .github repo) for hooks, templates, issue routing, and the PR-title workflow — one change propagates everywhere.
  • Repos carry only a config file and two small workflow stubs; no template copies to drift.
  • Commit/PR title format enforced both locally (commit-msg hook) and in CI (reusable workflow), with automatic type labels.
  • License hooks never modify LICENSE files.

Cons / risks

  • Version-pinned dependency on the org .github repository (tags are write-once; changes ship as a new tag + rev bump).
  • Template inheritance requires the org .github repository to remain public.

Related Issues / PRs

  • Resolves: TRI-1100

Related PRs:

Test plan

  • pre-commit validate-config passes; pre-commit run --files <PR diff> passes locally with the centralized hooks pinned to the .github branch SHA.
  • After .github#5 merges and v1.4.3 exists: the conventional-pr check validates this PR's own title and applies the ci label.
  • No LICENSE file content is changed by this PR.

Caveats

  • None beyond the merge-order note above.

Checklist

  • PR title follows <commit_type>: <Title> (conventional commit)
  • I ran pre-commit locally on all files changed by this PR and it passes
  • Copyright header is correct on all changed files
  • External contributors: I have read the Contribution guidelines and signed the Contributor License Agreement

Adopt the shared pre-commit baseline: two-line SPDX header, conventional
commit message validation (commit-msg stage), and the centralized
add-license / add-spdx-license hooks from developer_tools v0.2.0.
Run pre-commit CI only on files modified by the PR, and roll out the
standard issue templates and the simplified single PR template.

TRI-1100
@mc-nv mc-nv self-assigned this Jul 18, 2026
This was referenced Jul 18, 2026
Legal's Copyright / License Header Guidance specifies the SPDX form
without a comma after the year.

TRI-1100
@mc-nv
mc-nv marked this pull request as ready for review July 18, 2026 02:05
Human-readable type labels with enforced descriptions and colors.

TRI-1100
@github-actions github-actions Bot added CI/CD Continuous integration and workflow changes (ci: PRs) and removed ci labels Jul 20, 2026
@github-actions github-actions Bot added the chore Maintenance work, no production code change (chore: PRs) label Jul 20, 2026
mc-nv added 3 commits July 21, 2026 08:17
The add-license hook now fails when the LICENSE copyright year is
stale.

TRI-1100
Workflow files are license-processed again (only templates excluded);
refresh the stale copyright year this repo's pre-commit workflow
carried.

TRI-1100
Grant issues:write to the labeling job (review feedback).

TRI-1100
@mc-nv
mc-nv requested a review from pskiran1 July 22, 2026 15:12
@Vinya567

Copy link
Copy Markdown

@greptileai

@greptile-apps

greptile-apps Bot commented Jul 22, 2026

Copy link
Copy Markdown

Greptile Summary

This PR aligns the repository's CI tooling with the org-wide setup in triton-inference-server/.github. It adds a thin caller for the reusable conventional-pr workflow, overhauls the pre-commit workflow to run only on PR-modified files (using a null-delimited git diff | xargs pipeline), and extends .pre-commit-config.yaml with commit-message linting and the centralized add-license hook — all pinned to v1.4.3.

  • conventional-pr.yml (new): dual-event trigger (pull_request / pull_request_target) with a mutually-exclusive condition that routes same-repo PRs through the safe pull_request event and fork PRs through pull_request_target so the labeling job gets a writable token without running untrusted code.
  • pre-commit.yml (updated): replaces pre-commit/action with a manual pipeline that fetches only 2 commits, caches hook environments, and feeds changed-file paths (null-delimited, deletions filtered) to pre-commit run --files.
  • .pre-commit-config.yaml (updated): adds default_install_hook_types, fixes a whitespace quirk in flake8 args, and appends the conventional-pre-commit (commit-msg stage) and add-license hooks at v1.4.3.

Confidence Score: 5/5

Safe to merge; all changes are CI tooling with no impact on production code or existing workflows.

All three files touch only CI configuration. The dual-trigger pattern in conventional-pr.yml is correctly gated to prevent double-runs and privilege escalation from fork PRs. The pre-commit pipeline change (null-delimited git diff | xargs) is sound for the ubuntu runner. The only finding is a minor inconsistency in action version pinning style.

No files require special attention beyond confirming that v1.4.3 exists in triton-inference-server/.github before merging.

Important Files Changed

Filename Overview
.github/workflows/conventional-pr.yml New thin caller for the org-wide reusable conventional-pr workflow; dual-trigger pattern with mutually-exclusive condition is correctly implemented to avoid double-runs and prevent privilege escalation from fork PRs.
.github/workflows/pre-commit.yml Replaces pre-commit/action with a custom step; cache action uses a floating major-version tag (@v4) inconsistent with the other pinned actions, and the cache has no restore-keys fallback causing full misses on config changes.
.pre-commit-config.yaml Adds commit-msg hook and add-license hook at v1.4.3; default_install_hook_types correctly declares both stages; flake8 arg quoting fix is correct.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    PR[Pull Request event] --> E{Event type?}
    E -->|pull_request same-repo| C1{head.repo == repository?}
    E -->|pull_request_target fork| C2{head.repo != repository?}

    C1 -->|Yes| J1[conventional-pr job limited token]
    C1 -->|No| SKIP1[Job skipped]
    C2 -->|Yes| J2[conventional-pr job writable token]
    C2 -->|No| SKIP2[Job skipped]

    J1 --> RW[Calls reusable workflow at v1.4.3]
    J2 --> RW

    RW --> VA[Validate PR title vs Conventional Commits]
    VA --> LA[Derive and apply type label]
    LA --> OK[Pass]

    subgraph pre-commit CI
        PC1[checkout fetch-depth 2] --> PC2[setup-python]
        PC2 --> PC3[restore hook env cache]
        PC3 --> PC4[git diff HEAD^1 HEAD null-delimited]
        PC4 --> PC5{Files modified?}
        PC5 -->|Yes| PC6[pre-commit run on changed files only]
        PC5 -->|No| PC7[skip via no-run-if-empty]
    end
Loading

Reviews (2): Last reviewed commit: "ci: harden CI workflows and configs per ..." | Re-trigger Greptile

Comment thread .github/workflows/pre-commit.yml Outdated
Comment thread .github/workflows/conventional-pr.yml Outdated
- conventional-pr stub: dual pull_request/pull_request_target triggers
  so fork PRs from external contributors get labeled too (the reusable
  workflow never checks out PR code); explicit contents:read; pinned
  v1.4.3.
- pre-commit workflow: robust modified-files runner (null-delimited
  paths, deletion-only PRs handled, deleted paths filtered, no
  undocumented -r flag, cache keyed on config hash).
- flake8 args quoted correctly (the flow-scalar form split at commas
  and silently reduced the select list).
- hooks pinned to .github v1.4.3.

TRI-1100
@mc-nv

mc-nv commented Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Closing: the team is moving away from centralized org-level configuration in favor of per-repository self-contained setups (see triton-inference-server/server#8897 for the first decentralized implementation). Branch retained for reference. TRI-1100

@mc-nv mc-nv closed this Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance work, no production code change (chore: PRs) CI/CD Continuous integration and workflow changes (ci: PRs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants