Merge bugfix/gitleaks-protect-fallback into develop
This commit is contained in:
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
|
||||
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
|
||||
# unknown command — which would block every commit. Probe the subcommand first.
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
gl_sub=git
|
||||
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -462,6 +462,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
plugin cache or `claude plugin list`.
|
||||
|
||||
### Fixed
|
||||
- **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt
|
||||
package): the hook ran `gitleaks git --staged`, a subcommand that exists from
|
||||
8.19 only, so the "unknown command" exit 1 read as a leak. The generator now
|
||||
probes `gitleaks git --help` and falls back to `protect --staged`; the
|
||||
installed hooks are regenerated. T16c builds a `/usr/bin` symlink farm minus
|
||||
gitleaks instead of shortening PATH, which no longer hid a distro-packaged
|
||||
binary.
|
||||
- **gstack's shared helper tree was mostly unreachable.** gstack skills
|
||||
hardcode `~/.claude/skills/gstack/<path>` for shared assets, but
|
||||
`link.sh` and `install-plugins.sh` only ever linked `bin` and
|
||||
|
||||
+7
-2
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
|
||||
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
|
||||
# unknown command — which would block every commit. Probe the subcommand first.
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
gl_sub=git
|
||||
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
+7
-2
@@ -267,10 +267,15 @@ echo clean > clean.txt; git add clean.txt
|
||||
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
|
||||
|
||||
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
||||
# must not become a new single point of failure)
|
||||
# must not become a new single point of failure). A distro package puts
|
||||
# gitleaks in /usr/bin next to git, so "PATH without gitleaks" is a symlink
|
||||
# farm of /usr/bin minus gitleaks, not a shorter PATH.
|
||||
nogl="$WORK/nogl-bin"; mkdir -p "$nogl"
|
||||
for f in /usr/bin/*; do ln -s "$f" "$nogl/" 2>/dev/null; done
|
||||
rm -f "$nogl/gitleaks"
|
||||
echo clean2 > clean2.txt; git add clean2.txt
|
||||
# shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings
|
||||
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||
noleaks_out="$(PATH="$nogl" git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
||||
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
||||
|
||||
|
||||
+7
-2
@@ -381,10 +381,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
# gitleaks >= 8.19 scans the index with \`git --staged\`; older builds (Ubuntu's
|
||||
# 8.16 package) only know \`protect --staged\`, and \`git\` exits 1 there as an
|
||||
# unknown command — which would block every commit. Probe the subcommand first.
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
gl_sub=git
|
||||
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||
if ! gitleaks "\$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Details: gitleaks \$gl_sub --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user