Skip to content

Add pre-commit hook with requirements.txt lockfile-hygiene scan - #967

Merged
shrutiburman merged 1 commit into
mainfrom
lockfile-hygiene-python
Sep 23, 2026
Merged

shrutiburman merged 1 commit into
mainfrom
lockfile-hygiene-python

Conversation

@shrutiburman

Copy link
Copy Markdown
Contributor

Summary

  • Mirrors the uv-lockfile-hygiene CI gate locally: blocks a commit that introduces a non-public registry host in a staged requirements*.txt/uv.lock file.
  • No single safe rewrite target exists for a package URL (unlike npm/gems), so this blocks and reports rather than auto-rewriting.
  • Adds the githooks Makefile target and wires it into install, matching the pattern already shipped in twilio-node/twilio-php/twilio-ruby/twilio-go.

Test plan

  • make test run locally via the hook on commit (641 tests passed)
  • Verified the new scan reports clean against the current requirements.txt

🤖 Generated with Claude Code

Mirrors the uv-lockfile-hygiene CI gate locally: blocks a commit that
introduces a non-public registry host in a requirements*.txt/uv.lock file,
since there's no single safe rewrite target the way there is for npm/gems.
Adds the githooks Makefile target (matching twilio-node/php/ruby/go) so
`make install` wires it into .git/hooks/pre-commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@shrutiburman
shrutiburman merged commit 4ed7736 into main Sep 23, 2026
9 checks passed
@shrutiburman
shrutiburman deleted the lockfile-hygiene-python branch September 23, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants