#!/bin/sh # gitflow pre-commit — generated by gitflow_init. Do not hand-edit. # Mirrors gitflow_protected_base (lib/gitflow.sh). Drift caught by T10. gd=$(git rev-parse --git-dir) br=$(git symbolic-ref --short -q HEAD 2>/dev/null) git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — allow [ -f "$gd/MERGE_HEAD" ] && exit 0 # merge in progress — allow # Secret backstop (job7) — any branch, not just protected ones. Non-blocking # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). if command -v gitleaks >/dev/null 2>&1; then if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 echo " Details: gitleaks git --staged --no-banner" >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 exit 1 fi else echo "gitflow pre-commit: gitleaks not installed — secret scan skipped (https://github.com/gitleaks/gitleaks)." >&2 fi case "$br" in main|develop) ;; # protected — keep checking *) exit 0 ;; # working branch — allow esac # whitelist: all-staged-under-.claude/ (memory/doc/deploy helpers) — allow if [ -z "$(git diff --cached --name-only | grep -v '^\.claude/' | head -1)" ]; then exit 0 fi echo "gitflow pre-commit: BLOCKED — direct commit on '$br'." >&2 echo " Branch from the right base (feature/bugfix->develop, hotfix->main), or merge." >&2 echo " (.claude/** memory commits are exempt; --no-verify bypasses locally.)" >&2 exit 1