Pin pre-commit hooks to frozen revisions
This is a principle
A reusable technical claim: something I would want true in any of my work.
Claim. Pin every pre-commit hook repo to an immutable revision (a frozen
tag resolved to its SHA), not a floating branch or bare tag.
Why. Pre-commit hooks run arbitrary code on every commit and in CI, with
access to your working tree. A floating rev means the toolchain can change
under you between two clean checkouts - silently altering lint results or, worse,
executing tampered code. Freezing to a SHA (with the tag in a comment) makes the
toolchain reproducible and auditable; upgrades become explicit, reviewable diffs.
Snippet.
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: c59bba8fb259db0fec2bbb77ad8ba51ea7341b56 # frozen: v0.15.20
hooks:
- id: ruff-check
- id: ruff-format
How enforced. pre-commit autoupdate --freeze (or Dependabot's pre-commit
ecosystem) resolves tags to SHAs; the # frozen: <tag> comment keeps them
legible. Sibling of Pin GitHub Actions to full commit SHAs.
BacklinksΒΆ
The following pages link to this page: