forked from bchanot/claude
fix(gitflow): pre-commit gitleaks scan falls back to protect --staged on < 8.19
Ubuntu's gitleaks 8.16 package has no git subcommand, so the hook's "unknown command" exit 1 blocked every commit as a leak. Probe gitleaks git --help once, fall back to protect --staged; regenerate the installed hooks. T16c simulates a missing binary with a /usr/bin symlink farm minus gitleaks instead of a shorter PATH.
This commit is contained in:
+7
-2
@@ -9,10 +9,15 @@ git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — all
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
# gitleaks >= 8.19 scans the index with `git --staged`; older builds (Ubuntu's
|
||||
# 8.16 package) only know `protect --staged`, and `git` exits 1 there as an
|
||||
# unknown command — which would block every commit. Probe the subcommand first.
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
gl_sub=git
|
||||
gitleaks git --help >/dev/null 2>&1 || gl_sub=protect
|
||||
if ! gitleaks "$gl_sub" --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Details: gitleaks $gl_sub --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user