fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19
Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's "unknown command" exit 1 blocked every commit as a leak. Probe gitleaks git --help once, fall back to protect --staged; regenerate the installed hooks. T16c simulates a missing binary with a /usr/bin symlink farm minus gitleaks instead of a shorter PATH.
This commit is contained in:
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
|||||||
|
|
||||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||||
|
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
|
||||||
|
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
|
||||||
|
# unknown command — which would block every commit. Probe the subcommand first.
|
||||||
if command -v gitleaks >/dev/null 2>&1; then
|
if command -v gitleaks >/dev/null 2>&1; then
|
||||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
gl_sub=git
|
||||||
|
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||||
|
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
|
||||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -462,6 +462,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
plugin cache or `claude plugin list`.
|
plugin cache or `claude plugin list`.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
- **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt
|
||||||
|
package): the hook ran `gitleaks git --staged`, a subcommand that exists from
|
||||||
|
8.19 only, so the "unknown command" exit 1 read as a leak. The generator now
|
||||||
|
probes `gitleaks git --help` and falls back to `protect --staged`; the
|
||||||
|
installed hooks are regenerated. T16c builds a `/usr/bin` symlink farm minus
|
||||||
|
gitleaks instead of shortening PATH, which no longer hid a distro-packaged
|
||||||
|
binary.
|
||||||
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
||||||
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
||||||
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
||||||
|
|||||||
+7
-2
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
|||||||
|
|
||||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||||
|
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
|
||||||
|
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
|
||||||
|
# unknown command — which would block every commit. Probe the subcommand first.
|
||||||
if command -v gitleaks >/dev/null 2>&1; then
|
if command -v gitleaks >/dev/null 2>&1; then
|
||||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
gl_sub=git
|
||||||
|
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||||
|
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
|
||||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|||||||
+7
-2
@@ -267,10 +267,15 @@ echo clean > clean.txt; git add clean.txt
|
|||||||
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
|
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
|
||||||
|
|
||||||
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
||||||
# must not become a new single point of failure)
|
# must not become a new single point of failure). A distro package puts
|
||||||
|
# gitleaks in /usr/bin next to git, so "PATH without gitleaks" is a symlink
|
||||||
|
# farm of /usr/bin minus gitleaks, not a shorter PATH.
|
||||||
|
nogl="$WORK/nogl-bin"; mkdir -p "$nogl"
|
||||||
|
for f in /usr/bin/*; do ln -s "$f" "$nogl/" 2>/dev/null; done
|
||||||
|
rm -f "$nogl/gitleaks"
|
||||||
echo clean2 > clean2.txt; git add clean2.txt
|
echo clean2 > clean2.txt; git add clean2.txt
|
||||||
# shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings
|
# shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings
|
||||||
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
noleaks_out="$(PATH="$nogl" git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||||
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
||||||
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
||||||
|
|
||||||
|
|||||||
+7
-2
@@ -381,10 +381,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
|||||||
|
|
||||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||||
|
# gitleaks >= 8.19 scans the index with \`git --staged\`; older builds (Ubuntu's
|
||||||
|
# 8.16 package) only know \`protect --staged\`, and \`git\` exits 1 there as an
|
||||||
|
# unknown command — which would block every commit. Probe the subcommand first.
|
||||||
if command -v gitleaks >/dev/null 2>&1; then
|
if command -v gitleaks >/dev/null 2>&1; then
|
||||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
gl_sub=git
|
||||||
|
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||||
|
if ! gitleaks "\$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
echo " Details: gitleaks \$gl_sub --staged --no-banner" >&2
|
||||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user