fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19

Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's
"unknown command" exit 1 blocked every commit as a leak. Probe
gitleaks git --help once, fall back to protect --staged; regenerate the
installed hooks. T16c simulates a missing binary with a /usr/bin symlink
farm minus gitleaks instead of a shorter PATH.
This commit is contained in:
bastien
2026-09-28 21:40:58 +02:00
parent 1b95834865
commit 347073a0cc
5 changed files with 35 additions and 8 deletions
+7
View File
@@ -462,6 +462,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
plugin cache or `claude plugin list`.
### Fixed
- **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt
package): the hook ran `gitleaks git --staged`, a subcommand that exists from
8.19 only, so the "unknown command" exit 1 read as a leak. The generator now
probes `gitleaks git --help` and falls back to `protect --staged`; the
installed hooks are regenerated. T16c builds a `/usr/bin` symlink farm minus
gitleaks instead of shortening PATH, which no longer hid a distro-packaged
binary.
- **gstack's shared helper tree was mostly unreachable.** gstack skills
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
`link.sh` and `install-plugins.sh` only ever linked `bin` and