Skip to content

Mirror every local guard in CI

This is a principle

A reusable technical claim: something I would want true in any of my work.

Claim. Run the exact same pre-commit suite in CI that developers run locally - don't let the two drift into different rule sets.

Why. Commit-time hooks give fast feedback but are trivially bypassed (git commit --no-verify, a misconfigured environment, a contributor who never installed them). CI is the boundary that can't be skipped, so it must be the authority. Running the identical config in both places (rather than reimplementing a subset in CI) guarantees "passes locally" and "passes CI" mean the same thing, and removes the class of bug where a check exists in one place but not the other.

Snippet.

# governance.yml — CI runs the same prek/pre-commit config, on all files
- name: Run pre-commit hooks
  run: uv run --frozen --all-groups --all-extras prek run --all-files

How enforced. One CI job invokes the whole .pre-commit-config.yaml against --all-files, so local and CI enforcement are the same set by construction. The fast-feedback half is Guard invariants at commit-time, not review-time. Mind that a mirrored guard only fails honestly under Run CI steps under a strict shell (errexit, pipefail).

The following pages link to this page: