feat(gitflow): hooks in every repo, no per-project step
Global: `make link` generates githooks/ from lib/gitflow.sh and sets git's global core.hooksPath to ~/.claude/githooks, so every repo on the machine runs the pre-commit protection and the post-commit / post-merge push, even one that never ran gitflow init. A repo's own local core.hooksPath still wins, so hooks/session-start.sh calls `gitflow reconcile-hooks` once per session and rewrites a .githooks/ that lags the lib (LRN-114 automated); the pre-commit exemption now covers .githooks/** next to .claude/**. Per-repo opt-outs for a foreign clone: `git config gitflow.protect false` (branch model) and `git config gitflow.autopush false` (push). Both, and the GIT_CONFIG_GLOBAL= / GIT_CONFIG= env bypass, are static deny rules. `make test` and the two suites that commit on main export GIT_CONFIG_GLOBAL=/dev/null so the machine's global hooks never fire in throwaway repos. doctor gains "Git hooks" (global setting, githooks/ equal to the emitters) and "Scratchpad" (warn when TMPDIR sits on a tmpfs with usrquota: systemd caps each user at 80% of it, which killed two shells today, BLK-021). Tests: T18h, T19d, T20 (reconcile), T21 (whitelist and protect opt-out); this repo's own stale .githooks/ refreshed.
This commit is contained in:
+12
-7
@@ -194,14 +194,19 @@ flows (`/feat` `/bugfix` `/hotfix`) and the standalone memory/doc `chore`
|
||||
skills auto-branch on a protected base but commit in place on a working branch,
|
||||
never finishing — so those skills branch to `chore/*` via the aiguillage, not
|
||||
the `.claude/**` exemption. New/onboarded projects get the model + the
|
||||
versioned pre-commit hook via `gitflow init`. Advisory, so two deterministic
|
||||
backstops apply: the per-repo pre-commit hook (blocks code commits on
|
||||
main/develop, exempts `.claude/**` + merges + the root commit) and Gitea branch
|
||||
versioned hooks via `gitflow init`. Advisory, so deterministic backstops
|
||||
apply: the pre-commit hook (blocks code commits on main/develop, exempts
|
||||
`.claude/**` + `.githooks/**` + merges + the root commit) and Gitea branch
|
||||
protection on `main`/`develop`. Don't lean on `--no-verify` to bypass them.
|
||||
Every branch is pushed at `start` and every commit as it lands: `gitflow init`
|
||||
/ `install-hook` write post-commit and post-merge hooks that push to `origin`
|
||||
(warn, never block, when it fails); `GITFLOW_NO_PUSH=1` is for throwaway test
|
||||
repos only. A branch ahead of its upstream is a defect, not a state.
|
||||
Every branch is pushed at `start` and every commit as it lands by the
|
||||
post-commit and post-merge hooks (warn, never block, on failure). The three
|
||||
hooks run in EVERY repo on the machine: `make link` generates `githooks/`
|
||||
from the lib and sets git's global `core.hooksPath` to `~/.claude/githooks`;
|
||||
a repo that ran `gitflow init` keeps its own `.githooks/`, refreshed at
|
||||
session start when it lags the lib. Foreign clone: `git config
|
||||
gitflow.protect false` / `gitflow.autopush false`. `GITFLOW_NO_PUSH=1` is
|
||||
for throwaway test repos only. A branch ahead of its upstream is a defect,
|
||||
not a state.
|
||||
|
||||
## Security — non-negotiable defaults
|
||||
|
||||
|
||||
Reference in New Issue
Block a user