fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19

Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's
"unknown command" exit 1 blocked every commit as a leak. Probe
gitleaks git --help once, fall back to protect --staged; regenerate the
installed hooks. T16c simulates a missing binary with a /usr/bin symlink
farm minus gitleaks instead of a shorter PATH.
This commit is contained in:
bastien
2026-09-28 21:40:58 +02:00
parent 1b95834865
commit 347073a0cc
5 changed files with 35 additions and 8 deletions
+7 -2
View File
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking # Secret backstop (job7) — any branch, not just protected ones. Non-blocking
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
# unknown command — which would block every commit. Probe the subcommand first.
if command -v gitleaks >/dev/null 2>&1; then if command -v gitleaks >/dev/null 2>&1; then
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then gl_sub=git
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
echo " Details: gitleaks git --staged --no-banner" >&2 echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
exit 1 exit 1
fi fi
+7
View File
@@ -462,6 +462,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
plugin cache or `claude plugin list`. plugin cache or `claude plugin list`.
### Fixed ### Fixed
- **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt
package): the hook ran `gitleaks git --staged`, a subcommand that exists from
8.19 only, so the "unknown command" exit 1 read as a leak. The generator now
probes `gitleaks git --help` and falls back to `protect --staged`; the
installed hooks are regenerated. T16c builds a `/usr/bin` symlink farm minus
gitleaks instead of shortening PATH, which no longer hid a distro-packaged
binary.
- **gstack's shared helper tree was mostly unreachable.** gstack skills - **gstack's shared helper tree was mostly unreachable.** gstack skills
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
`link.sh` and `install-plugins.sh` only ever linked `bin` and `link.sh` and `install-plugins.sh` only ever linked `bin` and
+7 -2
View File
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking # Secret backstop (job7) — any branch, not just protected ones. Non-blocking
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
# unknown command — which would block every commit. Probe the subcommand first.
if command -v gitleaks >/dev/null 2>&1; then if command -v gitleaks >/dev/null 2>&1; then
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then gl_sub=git
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
echo " Details: gitleaks git --staged --no-banner" >&2 echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
exit 1 exit 1
fi fi
+7 -2
View File
@@ -267,10 +267,15 @@ echo clean > clean.txt; git add clean.txt
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null' chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
# T16c — gitleaks missing from PATH → warn, never block (defense in depth # T16c — gitleaks missing from PATH → warn, never block (defense in depth
# must not become a new single point of failure) # must not become a new single point of failure). A distro package puts
# gitleaks in /usr/bin next to git, so "PATH without gitleaks" is a symlink
# farm of /usr/bin minus gitleaks, not a shorter PATH.
nogl="$WORK/nogl-bin"; mkdir -p "$nogl"
for f in /usr/bin/*; do ln -s "$f" "$nogl/" 2>/dev/null; done
rm -f "$nogl/gitleaks"
echo clean2 > clean2.txt; git add clean2.txt echo clean2 > clean2.txt; git add clean2.txt
# shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings # shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$? noleaks_out="$(PATH="$nogl" git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]" chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"' chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
+7 -2
View File
@@ -381,10 +381,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking # Secret backstop (job7) — any branch, not just protected ones. Non-blocking
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
# gitleaks >= 8.19 scans the index with \`git --staged\`; older builds (Ubuntu's
# 8.16 package) only know \`protect --staged\`, and \`git\` exits 1 there as an
# unknown command — which would block every commit. Probe the subcommand first.
if command -v gitleaks >/dev/null 2>&1; then if command -v gitleaks >/dev/null 2>&1; then
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then gl_sub=git
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
if ! gitleaks "\$gl_sub" --staged --no-banner >/dev/null 2>&1; then
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
echo " Details: gitleaks git --staged --no-banner" >&2 echo " Details: gitleaks \$gl_sub --staged --no-banner" >&2
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
exit 1 exit 1
fi fi