FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Add check-signed-commit builtin hook by ebuildy · Pull Request #2725 · j178/prek · GitHub

/ prek Public

Add check-signed-commit builtin hook - #2725

Open
ebuildy wants to merge 4 commits into
j178:masterfrom
ebuildy:check-signed-commit
Open

ebuildy wants to merge 4 commits into
j178:masterfrom
ebuildy:check-signed-commit

Conversation

ebuildy commented Sep 15, 2026

Copy link
Copy Markdown

Why

Verifying commit signatures before a push has no good option today. Wiring git verify-commit up as a local hook runs into the problems described in #2720:

  • pass_filenames passes the commit-message file to git verify-commit, producing confusing "commit not found" errors.
  • commit-msg inspects the parent commit, not the one being written; post-commit can't block the push. Only pre-push can see the range and actually block it.
  • Getting that range requires the undocumented PRE_COMMIT_FROM_REF/PRE_COMMIT_TO_REF env vars.

How

Adds a builtin hook, check-signed-commit, that checks every non-merge commit in the range being pushed against Git's own signature status (%G? from git log), in a single git log call (no per-commit subprocess, no filename plumbing):

  • Defaults to the pre-push and manual stages, pass_filenames: none, always_run: true.
  • Range: PRE_COMMIT_FROM_REF..PRE_COMMIT_TO_REF when both are set; a lone PRE_COMMIT_TO_REF (root/orphan push) walks its full history; outside pre-push it falls back to HEAD.
  • --allow-status <CODE> (repeatable, default G, U) accepts any of Git's status codes (G/B/U/X/Y/R/E/N), so acceptance criteria (e.g. allowing SSH signatures without a trust store) are configurable rather than hardcoded.
  • On failure, reports each offending commit plus a legend of the status codes.

Example

repos:
  - repo: builtin
    hooks:
      - id: check-signed-commit
        args: [--allow-status, G, --allow-status, U]  # defaults shown; flag is optional
check for commit signatures..............................................Failed
- hook id: check-signed-commit
- exit code: 1

  a1b2c3d [N] no signature: fix typo

  Commit signature status codes:
    G  good signature
    ...

Closes #2720

🤖 Generated with Claude Code

ebuildy requested a review from j178 as a code owner September 15, 2026 04:37

codecov Bot commented Sep 15, 2026 •
edited
Loading

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.09804% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 94.19%. Comparing base (0cc3a1e) to head (3113aa6).

Files with missing lines Patch % Lines
...rek/src/hooks/builtin_hooks/check_signed_commit.rs 94.59% 10 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff            @@
##           master    #2725    +/-   ##
========================================
  Coverage   94.19%   94.19%            
========================================
  Files         142      143     +1     
  Lines       30292    30496   +204     
========================================
+ Hits        28534    28727   +193     
- Misses       1758     1769    +11     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

ebuildy marked this pull request as draft September 15, 2026 04:41

chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bc8f15d75f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

.arg("--no-merges")
.arg("-z")
.arg("--pretty=format:%h\u{1f}%G?\u{1f}%s")
.arg(range)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Check every ref in a multi-ref push

When one git push updates multiple refs, Git supplies one pre-push input line per ref, but parse_pre_push_info in crates/prek/src/cli/hook_impl.rs returns after selecting the first applicable line and exposes only that single range through these environment variables. Consequently, this git log checks only the first selected ref, so an unsigned commit reachable exclusively from a later branch or tag is pushed without inspection. The pre-push plumbing needs to retain all pushed ranges, and this hook must inspect each of them.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Ho good point! but it's an infrastructure gap, not something scoped to this PR's file, I could do another PR if you want

ebuildy force-pushed the check-signed-commit branch from bc8f15d to 099b4e7 Compare September 15, 2026 04:46

prek-ci-bot Bot commented Sep 15, 2026 •
edited
Loading

Copy link
Copy Markdown

📦 Cargo Bloat Comparison

.text size change: +3.25% (12.3 MiB → 12.7 MiB)

Expand for cargo-bloat output

Head Branch Results

File  .text     Size             Crate Name
0.1%   2.6% 332.0KiB        aws_lc_sys aws_lc_0_45_0_aes_gcm_encrypt_avx512
0.1%   2.6% 332.0KiB        aws_lc_sys aws_lc_0_45_0_aes_gcm_decrypt_avx512
0.0%   0.7%  96.5KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
0.0%   0.4%  50.1KiB              prek <<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.4%  48.7KiB annotate_snippets annotate_snippets::renderer::render::render
0.0%   0.3%  44.7KiB              prek prek::run::{closure#0}
0.0%   0.3%  43.9KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.3%  40.3KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
0.0%   0.3%  35.5KiB              prek prek::cli::run::run::run::{closure#0}
0.0%   0.2%  28.8KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.5KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  28.4KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_45_0_edwards25519_scalarmuldouble_alt
0.0%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_45_0_edwards25519_scalarmuldouble
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  24.5KiB              prek <prek::workspace::Project>::init_hooks::{closure#0}
4.2%  86.9%  11.0MiB                   And 20339 smaller methods. Use -n N to show more.
4.8% 100.0%  12.7MiB                   .text section size, the file size is 264.6MiB

Base Branch Results

File  .text     Size             Crate Name
0.1%   2.6% 332.0KiB        aws_lc_sys aws_lc_0_45_0_aes_gcm_encrypt_avx512
0.1%   2.6% 332.0KiB        aws_lc_sys aws_lc_0_45_0_aes_gcm_decrypt_avx512
0.0%   0.8%  96.5KiB              prek <prek::cli::Command as clap_builder::derive::Subcommand>::augment_subcommands
0.0%   0.4%  50.1KiB              prek <<prek::config::hook::HookWire as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.4%  48.7KiB annotate_snippets annotate_snippets::renderer::render::render
0.0%   0.3%  43.9KiB              prek <<prek::config::Config as serde_core::de::Deserialize>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::<&mut <serde_saphyr::de::deserializer::YamlDeserializer as serde_core::de::Deserializer>::deserialize_map::MA>
0.0%   0.3%  41.2KiB              prek prek::run::{closure#0}
0.0%   0.3%  40.3KiB              prek <prek::cli::RunOptions as clap_builder::derive::Args>::augment_args
0.0%   0.3%  36.8KiB              prek prek::cli::run::run::run::{closure#0}
0.0%   0.2%  28.8KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.6KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  28.4KiB      serde_saphyr <granit_parser::scanner::Scanner<granit_parser::input::str::StrInput>>::fetch_more_tokens
0.0%   0.2%  28.0KiB        aws_lc_sys aws_lc_0_45_0_edwards25519_scalarmuldouble_alt
0.0%   0.2%  27.5KiB        aws_lc_sys aws_lc_0_45_0_edwards25519_scalarmuldouble
0.0%   0.2%  27.2KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  27.0KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  26.9KiB              prek prek::archive::unpack::<fs_err::tokio::file::File, &std::path::PathBuf>::{closure#0}
0.0%   0.2%  24.5KiB              prek <prek::workspace::Project>::init_hooks::{closure#0}
4.1%  86.6%  10.7MiB                   And 20201 smaller methods. Use -n N to show more.
4.7% 100.0%  12.3MiB                   .text section size, the file size is 263.5MiB

prek-ci-bot Bot commented Sep 15, 2026 •
edited
Loading

Copy link
Copy Markdown

⚡️ Hyperfine Benchmarks

Summary: 0 regressions, 0 improvements above the 10% threshold.

Environment
  • OS: Linux 6.17.0-1022-azure
  • CPU: 4 cores
  • prek version: prek 0.5.3+21 (6c78505 2026-09-18)
  • Rust version: rustc 1.98.1 (48a229cea 2026-09-01)
  • Hyperfine version: hyperfine 1.20.0
CLI Commands

Benchmarking basic commands in the main repo:

prek --version

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base --version 2.3 ± 0.1 2.2 2.9 1.05 ± 0.07
prek-head --version 2.2 ± 0.1 2.0 2.5 1.00

prek list

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base list 9.1 ± 0.2 8.8 10.1 1.02 ± 0.04
prek-head list 8.9 ± 0.3 8.7 11.9 1.00

prek validate-config .pre-commit-config.yaml

⏭️ Skipped: .pre-commit-config.yaml not found

prek sample-config

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base sample-config 2.6 ± 0.0 2.5 2.7 1.06 ± 0.03
prek-head sample-config 2.4 ± 0.0 2.3 2.5 1.00
Cold vs Warm Runs

Comparing first run (cold) vs subsequent runs (warm cache):

prek run --all-files (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 38.0 ± 1.5 36.1 41.6 1.03 ± 0.05
prek-head run --all-files 36.8 ± 0.8 34.9 38.0 1.00

prek run --all-files (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 37.2 ± 1.3 35.2 39.7 1.00
prek-head run --all-files 37.2 ± 0.9 35.7 39.1 1.00 ± 0.04
Full Hook Suite

Running the builtin hook suite on the benchmark workspace:

prek run --all-files (full builtin hook suite)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --all-files 37.1 ± 1.0 35.0 39.1 1.00
prek-head run --all-files 37.1 ± 1.8 34.5 44.0 1.00 ± 0.05
Individual Hook Performance

Benchmarking each hook individually on the test repo:

prek run trailing-whitespace --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run trailing-whitespace --all-files 12.9 ± 0.4 12.3 13.8 1.01 ± 0.04
prek-head run trailing-whitespace --all-files 12.8 ± 0.3 12.1 13.6 1.00

prek run end-of-file-fixer --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run end-of-file-fixer --all-files 11.3 ± 0.9 10.3 15.2 1.03 ± 0.10
prek-head run end-of-file-fixer --all-files 10.9 ± 0.6 10.1 13.0 1.00

prek run check-json --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-json --all-files 7.9 ± 0.3 7.3 8.4 1.05 ± 0.05
prek-head run check-json --all-files 7.5 ± 0.3 7.1 8.1 1.00

prek run check-yaml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-yaml --all-files 7.6 ± 0.1 7.5 7.8 1.04 ± 0.02
prek-head run check-yaml --all-files 7.3 ± 0.1 7.1 7.7 1.00

prek run check-toml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-toml --all-files 7.6 ± 0.2 7.1 8.1 1.02 ± 0.04
prek-head run check-toml --all-files 7.4 ± 0.2 7.1 8.0 1.00

prek run check-xml --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-xml --all-files 7.6 ± 0.3 7.2 8.3 1.03 ± 0.06
prek-head run check-xml --all-files 7.4 ± 0.3 6.9 8.3 1.00

prek run detect-private-key --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run detect-private-key --all-files 10.9 ± 0.5 9.9 12.3 1.03 ± 0.06
prek-head run detect-private-key --all-files 10.6 ± 0.4 9.9 11.6 1.00

prek run fix-byte-order-marker --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run fix-byte-order-marker --all-files 12.9 ± 0.8 11.8 14.7 1.00
prek-head run fix-byte-order-marker --all-files 12.9 ± 0.8 11.5 14.6 1.00 ± 0.09
Installation Performance

Benchmarking hook installation (fast path hooks skip Python setup):

prek install-hooks (cold - no cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 4.5 ± 0.1 4.4 4.6 1.04 ± 0.02
prek-head install-hooks 4.4 ± 0.0 4.3 4.4 1.00

prek install-hooks (warm - with cache)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base install-hooks 4.5 ± 0.0 4.5 4.6 1.03 ± 0.02
prek-head install-hooks 4.4 ± 0.1 4.3 4.4 1.00
File Filtering/Scoping Performance

Testing different file selection modes:

prek run (staged files only)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run 21.2 ± 0.3 20.7 21.9 1.01 ± 0.02
prek-head run 21.0 ± 0.3 20.6 21.7 1.00

prek run --files '*.json' (specific file type)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --files '*.json' 5.2 ± 0.1 5.1 5.3 1.04 ± 0.02
prek-head run --files '*.json' 5.0 ± 0.1 4.9 5.2 1.00
Workspace Discovery & Initialization

Benchmarking hook discovery and initialization overhead:

prek run --dry-run --all-files (measures init overhead)

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run --dry-run --all-files 6.9 ± 0.1 6.7 7.0 1.03 ± 0.02
prek-head run --dry-run --all-files 6.6 ± 0.1 6.5 6.8 1.00
Meta Hooks Performance

Benchmarking meta hooks separately:

prek run check-hooks-apply --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-hooks-apply --all-files 8.1 ± 0.1 8.0 8.3 1.03 ± 0.02
prek-head run check-hooks-apply --all-files 7.9 ± 0.1 7.8 8.1 1.00

prek run check-useless-excludes --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run check-useless-excludes --all-files 8.1 ± 0.0 7.9 8.1 1.03 ± 0.02
prek-head run check-useless-excludes --all-files 7.8 ± 0.1 7.6 8.0 1.00

prek run identity --all-files

Command Mean [ms] Min [ms] Max [ms] Relative
prek-base run identity --all-files 7.0 ± 0.0 6.9 7.1 1.02 ± 0.02
prek-head run identity --all-files 6.9 ± 0.1 6.7 7.2 1.00

ebuildy force-pushed the check-signed-commit branch from 099b4e7 to ed34c0c Compare September 15, 2026 05:01
ebuildy force-pushed the check-signed-commit branch from ed34c0c to d8a22dc Compare September 15, 2026 05:19
ebuildy marked this pull request as ready for review September 15, 2026 05:29
ebuildy marked this pull request as draft September 15, 2026 05:30
ebuildy marked this pull request as ready for review September 18, 2026 14:09

ebuildy commented Sep 18, 2026

Copy link
Copy Markdown
Author

Ready for review ! I am doing another PR related , to check the DCO signoff status

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Builtin hook to verify commits are signed (check-signed-commit)

2 participants


Back | FazBrowse Home | New Git URL