forked from bchanot/claude
job7 step C: gitleaks backstop — .gitleaks.toml, pre-commit hook, make scan-secrets
Pre-commit (lib/gitflow.sh emit-hook) now runs `gitleaks git --staged` right after the root-commit/merge-in-progress guard, on ANY branch — not gated by branch protection, since secrets shouldn't land anywhere. Non-blocking if gitleaks isn't installed (warn + pass). gitleaks 8.30.1: `protect` isn't listed in --help anymore (still runs, but undocumented) — used the documented `git --staged` equivalent instead. .gitleaks.toml allowlists the 3 false-positive classes from the job7 triage (marketplace.json 40-hex "sha" fields, superpowers ws-protocol.test.js nonce, git-game test-secret-* fixtures) plus a 4th entry for ~/.claude/.env itself — not a false positive, but scanning our own canonical vault (BDR-026) is pure noise for a tool meant to catch stray copies. All 4 verified empirically against the real flagged files/values before being added, not assumed from gitleaks' docs. `make scan-secrets` scans this repo's git history + ~/.claude (dir scan), redacted JSON to .audit/ (verified: --redact scrubs Match/Secret in the report itself, not just console logs — safe to commit). Repo: 0 findings. ~/.claude: 18 remaining across 8 files — 5 match the known job7 triage (pending the GO-gated purge in step D), 3 are new discoveries outside the original triage scope (flagged for the user, not characterized further — never read a flagged file's content past what gitleaks' redacted report gives you). lib/gitflow-test.sh T16: fake secret on a feature branch (not main/develop) → blocked, proving the check isn't gated by branch protection; clean commit passes; PATH without gitleaks → warns and still commits. 96/96 green.
This commit is contained in:
@@ -231,6 +231,31 @@ chk "T15 nothing staged" '[ -z "$(git diff --cached --name-only)" ]'
|
||||
chk "T15 no .gitignore written" '[ ! -e .gitignore ]'
|
||||
chk "T15 no .githooks written" '[ ! -d .githooks ]'
|
||||
|
||||
echo "T16 — gitleaks pre-commit backstop (job7), independent of branch protection"
|
||||
newrepo gl; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start feature glwork >/dev/null 2>&1
|
||||
|
||||
# T16a — a real secret pattern staged on a working branch (not main/develop,
|
||||
# proving this backstop is NOT gated by the branch-protection check above it)
|
||||
printf 'aws_access_key_id = AKIA%s\n' "GDR5XRBXYARW2I5N" > secret.txt
|
||||
git add secret.txt
|
||||
gl_out="$(git commit -q -m "add secret" 2>&1)"; gl_rc=$?
|
||||
chk "T16a fake secret on feature branch → blocked" "[ $gl_rc -ne 0 ]"
|
||||
chk "T16a message mentions gitleaks" 'printf "%s" "$gl_out" | grep -qi gitleaks'
|
||||
chk "T16a nothing committed" '! git log --oneline 2>/dev/null | grep -q "add secret"'
|
||||
git restore --staged secret.txt 2>/dev/null || true; rm -f secret.txt
|
||||
|
||||
# T16b — a clean commit is unaffected
|
||||
echo clean > clean.txt; git add clean.txt
|
||||
chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/null'
|
||||
|
||||
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
||||
# must not become a new single point of failure)
|
||||
echo clean2 > clean2.txt; git add clean2.txt
|
||||
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
||||
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
||||
|
||||
echo
|
||||
echo "==== RESULT: $PASS passed, $FAIL failed ===="
|
||||
[ "$FAIL" -eq 0 ]
|
||||
|
||||
@@ -221,6 +221,19 @@ br=\$(git symbolic-ref --short -q HEAD 2>/dev/null)
|
||||
git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — allow
|
||||
[ -f "\$gd/MERGE_HEAD" ] && exit 0 # merge in progress — allow
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "gitflow pre-commit: gitleaks not installed — secret scan skipped (https://github.com/gitleaks/gitleaks)." >&2
|
||||
fi
|
||||
|
||||
case "\$br" in
|
||||
$GITFLOW_MAIN|$GITFLOW_DEVELOP) ;; # protected — keep checking
|
||||
*) exit 0 ;; # working branch — allow
|
||||
|
||||
Reference in New Issue
Block a user