diff --git a/.githooks/pre-commit b/.githooks/pre-commit index ef3abef..a42373a 100755 --- a/.githooks/pre-commit +++ b/.githooks/pre-commit @@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all # Secret backstop (job7) — any branch, not just protected ones. Non-blocking # if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root). +# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's +# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an +# unknown command — which would block every commit. Probe the subcommand first. if command -v gitleaks >/dev/null 2>&1; then - if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then + gl_sub=git + gitleaks git --help >/dev/null 2>&1 || gl_sub=protect + if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2 - echo " Details: gitleaks git --staged --no-banner" >&2 + echo " Details: gitleaks $gl_sub --staged --no-banner" >&2 echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2 exit 1 fi diff --git a/.githooks/reference-transaction b/.githooks/reference-transaction new file mode 100755 index 0000000..1e2cab1 --- /dev/null +++ b/.githooks/reference-transaction @@ -0,0 +1,15 @@ +#!/bin/sh +# gitflow reference-transaction — generated by gitflow_init. Do not hand-edit. +# Refuses deleting (or renaming) main / develop, whatever the +# command. Mirrors gitflow_protected_base (lib/gitflow.sh). +[ "$1" = prepared ] || exit 0 +while read -r _old new ref; do + case "$ref" in refs/heads/main|refs/heads/develop) ;; *) continue ;; esac + case "$new" in *[!0]*) continue ;; esac # new value not all-zeros → an update, not a deletion + # Per-repo opt-out (a foreign clone): git config gitflow.protect false + [ "$(git config --bool --default true gitflow.protect)" = false ] && exit 0 + echo "gitflow reference-transaction: BLOCKED — deleting '$ref', a protected base." >&2 + echo " main and develop are never deleted or renamed. A merged working branch: gitflow.sh delete " >&2 + exit 1 +done +exit 0