From 347073a0ccc553d99b19f59d83e5bde0510ae55d Mon Sep 17 00:00:00 2001 From: bastien Date: Mon, 28 Sep 2026 21:40:58 +0200 Subject: [PATCH] fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19 Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's "unknown command" exit 1 blocked every commit as a leak. Probe gitleaks git --help once, fall back to protect --staged; regenerate the installed hooks. T16c simulates a missing binary with a /usr/bin symlink farm minus gitleaks instead of a shorter PATH. --- .githooks/pre-commit | 9 +++++++-- CHANGELOG.md | 7 +++++++ githooks/pre-commit | 9 +++++++-- lib/gitflow-test.sh | 9 +++++++-- lib/gitflow.sh | 9 +++++++-- 5 files changed, 35 insertions(+), 8 deletions(-) diff --git a/.githooks/pre-commit b/.githooks/pre-commit index ef3abef..a42373a 100755 --- a/.githooks/pre-commit +++ b/.githooks/pre-commit @@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all # Secret backstop (job7) — any branch, not just protected ones. Non-blocking # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). +# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's +# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an +# unknown command — which would block every commit. Probe the subcommand first. if command -v gitleaks >/dev/null 2>&1; then - if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then + gl_sub=git + gitleaks git --help >/dev/null 2>&1 || gl_sub=protect + if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 - echo " Details: gitleaks git --staged --no-banner" >&2 + echo " Details: gitleaks $gl_sub --staged --no-banner" >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 exit 1 fi diff --git a/CHANGELOG.md b/CHANGELOG.md index 867c199..91d64d6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -462,6 +462,13 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). plugin cache or `claude plugin list`. ### Fixed +- **gitflow pre-commit blocked every commit with gitleaks 8.16** (Ubuntu's apt + package): the hook ran `gitleaks git --staged`, a subcommand that exists from + 8.19 only, so the "unknown command" exit 1 read as a leak. The generator now + probes `gitleaks git --help` and falls back to `protect --staged`; the + installed hooks are regenerated. T16c builds a `/usr/bin` symlink farm minus + gitleaks instead of shortening PATH, which no longer hid a distro-packaged + binary. - **gstack's shared helper tree was mostly unreachable.** gstack skills hardcode `~/.claude/skills/gstack/` for shared assets, but `link.sh` and `install-plugins.sh` only ever linked `bin` and diff --git a/githooks/pre-commit b/githooks/pre-commit index ef3abef..a42373a 100755 --- a/githooks/pre-commit +++ b/githooks/pre-commit @@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all # Secret backstop (job7) — any branch, not just protected ones. Non-blocking # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). +# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's +# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an +# unknown command — which would block every commit. Probe the subcommand first. if command -v gitleaks >/dev/null 2>&1; then - if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then + gl_sub=git + gitleaks git --help >/dev/null 2>&1 || gl_sub=protect + if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 - echo " Details: gitleaks git --staged --no-banner" >&2 + echo " Details: gitleaks $gl_sub --staged --no-banner" >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 exit 1 fi diff --git a/lib/gitflow-test.sh b/lib/gitflow-test.sh index a961a7e..0b95df5 100644 --- a/lib/gitflow-test.sh +++ b/lib/gitflow-test.sh @@ -267,10 +267,15 @@ echo clean > clean.txt; git add clean.txt chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null' # T16c — gitleaks missing from PATH → warn, never block (defense in depth -# must not become a new single point of failure) +# must not become a new single point of failure). A distro package puts +# gitleaks in /usr/bin next to git, so "PATH without gitleaks" is a symlink +# farm of /usr/bin minus gitleaks, not a shorter PATH. +nogl="$WORK/nogl-bin"; mkdir -p "$nogl" +for f in /usr/bin/*; do ln -s "$f" "$nogl/" 2>/dev/null; done +rm -f "$nogl/gitleaks" echo clean2 > clean2.txt; git add clean2.txt # shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings -noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$? +noleaks_out="$(PATH="$nogl" git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$? chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]" chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"' diff --git a/lib/gitflow.sh b/lib/gitflow.sh index b885603..47b6e93 100644 --- a/lib/gitflow.sh +++ b/lib/gitflow.sh @@ -381,10 +381,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all # Secret backstop (job7) — any branch, not just protected ones. Non-blocking # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). +# gitleaks >= 8.19 scans the index with \`git --staged\`; older builds (Ubuntu's +# 8.16 package) only know \`protect --staged\`, and \`git\` exits 1 there as an +# unknown command — which would block every commit. Probe the subcommand first. if command -v gitleaks >/dev/null 2>&1; then - if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then + gl_sub=git + gitleaks git --help >/dev/null 2>&1 || gl_sub=protect + if ! gitleaks "\$gl_sub" --staged --no-banner >/dev/null 2>&1; then echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 - echo " Details: gitleaks git --staged --no-banner" >&2 + echo " Details: gitleaks \$gl_sub --staged --no-banner" >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 exit 1 fi