Skip to content

Pin pre-commit hooks to frozen revisions

This is a principle

A reusable technical claim: something I would want true in any of my work.

Claim. Pin every pre-commit hook repo to an immutable revision (a frozen tag resolved to its SHA), not a floating branch or bare tag.

Why. Pre-commit hooks run arbitrary code on every commit and in CI, with access to your working tree. A floating rev means the toolchain can change under you between two clean checkouts - silently altering lint results or, worse, executing tampered code. Freezing to a SHA (with the tag in a comment) makes the toolchain reproducible and auditable; upgrades become explicit, reviewable diffs.

Snippet.

- repo: https://github.com/astral-sh/ruff-pre-commit
  rev: c59bba8fb259db0fec2bbb77ad8ba51ea7341b56  # frozen: v0.15.20
  hooks:
  - id: ruff-check
  - id: ruff-format

How enforced. pre-commit autoupdate --freeze (or Dependabot's pre-commit ecosystem) resolves tags to SHAs; the # frozen: <tag> comment keeps them legible. Sibling of Pin GitHub Actions to full commit SHAs.

The following pages link to this page: