# Pre-commit hooks for LEDMatrix # Install: pip install pre-commit && pre-commit install # Run manually: pre-commit run --all-files repos: - repo: https://github.com/pre-commit/pre-commit-hooks rev: v4.5.0 hooks: - id: trailing-whitespace - id: end-of-file-fixer - id: check-yaml - id: check-json - id: check-added-large-files args: ['--maxkb=1000'] - id: check-merge-conflict - repo: https://github.com/PyCQA/flake8 rev: 7.0.0 hooks: - id: flake8 args: ['--select=E9,F63,F7,F82,B', '--ignore=E501'] additional_dependencies: [flake8-bugbear] - repo: local hooks: - id: no-bare-except name: Check for bare except clauses entry: bash -c 'if grep -rn "except:\s*pass" src/; then echo "Found bare except:pass - please handle exceptions properly"; exit 1; fi' language: system types: [python] pass_filenames: false - id: no-hardcoded-paths name: Check for hardcoded user paths entry: bash -c 'if grep -rn "/home/chuck/" src/; then echo "Found hardcoded user paths - please use relative paths or config"; exit 1; fi' language: system types: [python] pass_filenames: false # The mypy ratchet -- the same check as CI's "Type check (mypy ratchet)" # job: mypy on exactly the modules listed in mypy-clean.txt. Run it with # pre-commit run mypy --hook-stage manual # A local hook rather than mirrors-mypy so mypy sees the packages installed # from requirements.txt, as CI does; an isolated hook env without them types # PIL, requests and friends as Any and reports different errors. Needs # mypy==1.20.2 (the version CI pins) in the environment you commit from. - repo: local hooks: - id: mypy name: mypy (ratchet, mypy-clean.txt) entry: python scripts/check_types.py language: system pass_filenames: false always_run: true stages: [manual] - repo: https://github.com/PyCQA/bandit rev: 1.8.3 hooks: - id: bandit args: - '-r' - '-ll' - '-c' - 'bandit.yaml' - '-x' - './tests,./test,./venv,./.venv,./scripts/prove_security.py,./rpi-rgb-led-matrix-master' - repo: https://github.com/gitleaks/gitleaks rev: v8.24.3 hooks: - id: gitleaks