The pre-commit framework from pre-commit Framework runs both tools on staged templates. Local hooks with language: system call the installed tools; cfn-lint 2,641 's published hook (repo: https://github.com/aws-cloudformation/cfn-lint 2,641 , rev: v1.57.0) would install its own pinned copy instead:
# Checks run by `git commit` after `pre-commit install`
repos:
- repo: local
hooks:
- id: cfn-lint
name: cfn-lint
entry: cfn-lint
language: system
files: ^infra/[^/]+\.yaml$
- id: cfn-guard
name: cfn-guard (BookNest rules)
entry: cfn-guard validate --show-summary fail --rules infra/rules/booknest.guard --data
language: system
files: ^infra/(catalog|wishlist|reader-role)\.yaml$Each hook receives only staged paths that match its files pattern, so the rule tests under infra/rules/ are not linted as templates. Committing the draft from cfn-lint with the configuration:
cd ~/v5-ch7/booknest
pre-commit install
cp ~/v5-ch7/scratch/reviews.yaml infra/
git add .pre-commit-config.yaml infra/rules infra/reviews.yaml
git commit -m "Add the reviews table"pre-commit installed at .git/hooks/pre-commit cfn-lint.................................................................Failed - hook id: cfn-lint - exit code: 6 W2001 Parameter Owner not used. infra/reviews.yaml:4:3 ... cfn-guard (BookNest rules)...........................(no files to check)Skipped
The commit was refused. After git rm --cached infra/reviews.yaml, a commit of the configuration alone went through, both hooks reporting (no files to check)Skipped, since no template was staged.
git commit --no-verify skips local hooks, so CI must run the same checks as the real gate (Deploying from Actions).