105 lines
4.0 KiB
Markdown
105 lines
4.0 KiB
Markdown
---
|
|
source_keys:
|
|
- context7-pre-commit-com
|
|
- pre-commit-com
|
|
- context7-pre-commit-hooks
|
|
- pre-commit-hooks-github
|
|
---
|
|
|
|
# Hook Recommendations by Language / Context
|
|
|
|
Use this table when creating a config from scratch or recommending hooks to add.
|
|
Always check the existing config for duplicates before proposing.
|
|
|
|
## Universal (recommend for every repo)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `end-of-file-fixer` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Ensures files end with a newline — prevents spurious diffs |
|
|
| `trailing-whitespace` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Strips trailing whitespace — prevents invisible diff noise |
|
|
| `check-merge-conflict` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Catches unresolved merge markers before commit |
|
|
| `detect-private-key` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Blocks PEM private key material |
|
|
|
|
## Shell (`.sh`)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `shellcheck` | `https://github.com/jumanjihouse/pre-commit-hooks` | `3.0.0` | Static analysis for shell scripts; catches common errors |
|
|
|
|
Recommended args: `args: [--severity=warning]`
|
|
|
|
## Python (`.py`)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `check-ast` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Validates Python files parse as valid AST |
|
|
| `check-builtin-literals` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Enforces literal syntax for `dict()`, `list()` |
|
|
|
|
For formatting: check if `black`, `ruff`, or `isort` is already configured in `pyproject.toml` before recommending them.
|
|
|
|
## JSON (`.json`)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `check-json` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Validates JSON parses correctly |
|
|
| `pretty-format-json` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Auto-formats JSON (fixer — warns user to re-stage after commit) |
|
|
|
|
## YAML (`.yaml`, `.yml`)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `check-yaml` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Validates YAML parses correctly |
|
|
|
|
For Kubernetes/Helm YAML with custom tags, add `args: ['--unsafe']` and `exclude: ^helm/templates/`.
|
|
|
|
## TOML (`.toml`)
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `check-toml` | `https://github.com/pre-commit/pre-commit-hooks` | `v6.0.0` | Validates TOML parses correctly |
|
|
|
|
## Secrets / security
|
|
|
|
| Hook ID | Repo | Rev | Rationale |
|
|
|---------|------|-----|-----------|
|
|
| `gitleaks` | `https://github.com/gitleaks/gitleaks` | `v8.21.2` | Scans for secrets and high-entropy strings |
|
|
|
|
## Commit message
|
|
|
|
| Hook ID | Repo | Rev | Stage | Rationale |
|
|
|---------|------|-----|-------|-----------|
|
|
| `conventional-pre-commit` | `https://github.com/compilerla/conventional-pre-commit` | `v2.4.0` | `commit-msg` | Enforces Conventional Commits format |
|
|
|
|
When adding commit-msg hooks, also add `default_install_hook_types: [pre-commit, commit-msg]` to the top-level config if not already present.
|
|
|
|
## Meta-validation (add last, after all other repos)
|
|
|
|
```yaml
|
|
- repo: meta
|
|
hooks:
|
|
- id: check-hooks-apply # catches hooks that match no files
|
|
- id: check-useless-excludes # catches exclude patterns that match no files
|
|
```
|
|
|
|
## Local hooks (repo: local)
|
|
|
|
Use for repo-specific scripts that don't belong in an external hook repo.
|
|
|
|
```yaml
|
|
- repo: local
|
|
hooks:
|
|
- id: run-tests
|
|
name: Run test suite
|
|
entry: bash tests/run-tests.sh
|
|
language: unsupported_script
|
|
pass_filenames: false
|
|
always_run: true
|
|
stages: [pre-push]
|
|
```
|
|
|
|
Language choices for local hooks:
|
|
- `unsupported` — system PATH tool (pre-commit does not manage env)
|
|
- `unsupported_script` — script at a repo-relative path
|
|
- `fail` — always-fail guard; `entry` text becomes the error message
|
|
- `python` — isolated venv; use `additional_dependencies` for pip packages
|