forked from bchanot/claude
chore(gitflow): regenerate installed pre-commit hook to include job7 gitleaks backstop
Root cause: job7/17bdd08 added the gitleaks scan to the hook GENERATOR
(_gitflow_emit_pre_commit) but the installed .githooks/pre-commit is only
(re)written by 'gitflow init'/'install-hook' — never invoked on this repo after
job7. No mechanism propagates a generator change to already-installed hooks, and
T10 diffs only the allow/block verdict (not content), so the drift was silent.
The installed hook (620071b, 2026-06-29) predated the gitleaks addition by 8 days.
Regenerated via 'gitflow.sh install-hook'; installed hook now == fresh emit.
Gates: grep -c gitleaks=7; negative test (staged AKIA... on a working branch)
BLOCKED with exit 1; make test GREEN. Review finding A2 (P0). A content-drift
assertion is added to make test in the fil-rouge commit.
This commit is contained in:
@@ -7,6 +7,19 @@ br=$(git symbolic-ref --short -q HEAD 2>/dev/null)
|
||||
git rev-parse --verify -q HEAD >/dev/null 2>&1 || exit 0 # root commit — allow
|
||||
[ -f "$gd/MERGE_HEAD" ] && exit 0 # merge in progress — allow
|
||||
|
||||
# Secret backstop (job7) — any branch, not just protected ones. Non-blocking
|
||||
# if gitleaks isn't installed; auto-discovers ./.gitleaks.toml (repo root).
|
||||
if command -v gitleaks >/dev/null 2>&1; then
|
||||
if ! gitleaks git --staged --no-banner >/dev/null 2>&1; then
|
||||
echo "gitflow pre-commit: BLOCKED — gitleaks found a secret in staged changes." >&2
|
||||
echo " Details: gitleaks git --staged --no-banner" >&2
|
||||
echo " Genuine false-positive? add an allowlist rule to .gitleaks.toml — never bypass with --no-verify." >&2
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
echo "gitflow pre-commit: gitleaks not installed — secret scan skipped (https://github.com/gitleaks/gitleaks)." >&2
|
||||
fi
|
||||
|
||||
case "$br" in
|
||||
main|develop) ;; # protected — keep checking
|
||||
*) exit 0 ;; # working branch — allow
|
||||
|
||||
Reference in New Issue
Block a user