Checks run at three points: on staged files at commit time, at push time, and in GitHub Actions. All three repositories use husky, lint-staged and commitlint. The prepare script in each package.json installs the hooks when you run the install command.
The docs/CI_AND_HOOKS.md file in each repository describes more pre-push checks than the hooks actually run. The tables below reflect the hook files and workflow files as they are.

Hooks

pre-commit

All three run lint-staged. In the backend, lint-staged lints each staged file directly. Files outside a package’s src folder, such as prisma.config.ts, are skipped by pnpm lint but are linted here, so the no-direct-process-env rule can fail a commit that touches them.

commit-msg

All three run commitlint on the message. See Branches and commits.

pre-push

No pre-push hook runs a type-check or tests. Run those yourself. See Testing.

GitHub Actions

backend

The gitleaks step scans the whole history, so a secret committed once keeps failing CI until the history or the gitleaks config deals with it. Rotate any secret that was ever committed. pnpm cve:check runs the same CVE checks locally through tools/check-cves.sh. It installs osv-scanner into ~/.local/bin when it is missing.

frontend

.github/dependabot.yml opens grouped weekly npm update pull requests against dev, at most five at a time, and ignores major version bumps.

mobile

Mobile builds and OTA updates are not run by CI. They are run by hand with the EAS CLI. See Mobile builds.

What CI does not cover

  • The deploy workflows that run on a push to dev do not wait for ci.yml. In the backend, ci.yml does not run on a push to dev at all. A direct push to dev is deployed without lint, type-check or tests having run in CI.
  • Playwright end-to-end tests.
  • The mobile node:test scripts.
  • Any check that the two backend Prisma schemas agree with each other.
Because of the first point, run the full local checks before you push to dev, or go through a pull request.

Turborepo task graph

DATABASE_URL and CI pass through to every task through globalPassThroughEnv.

Adding a check

Add it at the cheapest layer first, then in CI, then document it. A check that only runs in CI wastes a run on every typo. A check that only runs locally is skipped by the next person who clones the repository without hooks.