The local hook pinned ruff to v0.15.1. CI ran a bare `pip install ruff`
and got whatever astral had shipped that morning. Those are not the same
checker, so `just lint` passing locally said nothing about CI, and the
gap widened on astral's release schedule rather than on ours.
That is exactly how dlp-scanner went red: 0.16.0 stabilized PLR0917 out
of preview, CI adopted it unasked, and four signatures failed a rule the
local hook had never once run.
Pin CI to the rev in .pre-commit-config.yaml instead of hardcoding a
second version here. The hook rev is now the only place a ruff version
is written, so bumping it moves both sides in the same commit and the
two can no longer disagree. If that rev ever goes missing or stops
looking like a version, the step exits non-zero rather than falling
back to unpinned - both failure modes were tested.
Bump the pin 0.15.1 -> 0.16.1, which is the version CI was already
silently using. Censused first: all 18 ruff projects pass under 0.16.1,
and the freshly built hook env reports 0.16.1 at the binary and still
catches the original four errors in an unfixed tree.
- Crystal: shards install doesn't build dev-dep binaries. Build ameba
explicitly via crystal build lib/ameba/bin/ameba.cr -o bin/ameba so
the lint step finds it.
- V: vlang/setup-v installs a V build whose fmt rules drift from local
V 0.5.1 (same version string, different formatter behavior). Make
v fmt advisory and gate the job on v vet only.
pnpm latest on Node 22 resolves to pnpm 11 which rejects lockfileVersion
9.0 lockfiles with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Pinning to pnpm 10
keeps compatibility with existing lockfiles. .npmrc sets
strict-dep-builds=false so build-script warnings don't hard-fail the
frozen install.
Node.js bumped to 22 in lint workflow (pnpm 11.x requires >=22.13).
Extract goconst-flagged string literals in secrets-scanner to named
constants. Carry along monitor-dashboard docker/package fixes.
Replace broken jiro4989/setup-nim-action@v2 with direct choosenim
install. Add ebpf tracer and dlp scanner to lint matrix. Update SBOM
generator badge to Project #24 and add source/docs links in main
README. Bump project count to 24/67.