developis DEV and the default branch. Open pull requests againstdevelop.mainis PRD. Do not target it unless the change is a production hotfix.
Verity uses pre-commit to run fast, deterministic lint
locally — before code reaches CI. The same .pre-commit-config.yaml is run by the
pre-commit job in GitHub Actions, so local and CI checks never drift apart.
pipx install pre-commit # or: pip install pre-commit / brew install pre-commit
pre-commit install # wires up both pre-commit and pre-push hookspre-commit install activates both hook stages in one command
(default_install_hook_types is set in the config).
Hooks run automatically on git commit (and git push for clippy). To run them by hand:
pre-commit run --all-files # run every hook against the whole tree
pre-commit run typos # run a single hookIf a hook auto-fixes a file (e.g. cargo fmt, end-of-file-fixer), re-stage the
change and commit again.
Local hooks give fast feedback; GitHub Actions is the enforcement gate that also
catches --no-verify bypasses and contributors who never ran pre-commit install.
| Check | Local (pre-commit) | GitHub Actions |
|---|---|---|
trailing-whitespace, end-of-file-fixer, check-yaml, mixed-line-ending |
commit | Quality / pre-commit |
typos (spell check) |
commit | Quality / pre-commit |
markdownlint-cli2 (docs/src) |
commit | Quality / pre-commit |
cargo fmt |
commit | Rust / check |
cargo clippy |
pre-push | Rust / check |
cargo test / build |
— | Rust / check |
cargo deny |
— | Rust / deny |
| secret scan (betterleaks) | — | Secret Scan |
| mdBook build / deploy | — | Docs |
| offline link check | — | Docs / links |
| online link check (weekly) | — | Quality / link-check |
The Quality / pre-commit job runs pre-commit run --all-files with SKIP=fmt,clippy:
the Rust hooks need the toolchain, so they run in the Rust workflow where the
toolchain and build cache live.
Hook versions are pinned by rev in .pre-commit-config.yaml and kept current by
Dependabot (the pre-commit ecosystem in .github/dependabot.yml). Lint settings
live in the existing config files (_typos.toml, .markdownlint.jsonc, rustfmt.toml)
— the pre-commit config does not duplicate them.