build(security-review): prune .claude worktrees from deterministic scanners

Agent worktrees under .claude/worktrees/ are full repo copies; the cfn-lint
find|xargs template scan overflowed ('command line cannot be assembled') and the
pre-push hook fail-closed to BLOCK whenever a worktree was present. Prune .claude
in the cfn-lint find + semgrep/checkov excludes, and gitignore .claude/ so it is
never scanned or committed. Unblocks main-tree pushes during parallel agent work.
This commit is contained in:
Adam Moussa 2026-06-18 15:51:28 -04:00
parent 9d7d03d6db
commit b8b84337f3
2 changed files with 6 additions and 3 deletions

3
.gitignore vendored
View file

@ -10,3 +10,6 @@ __pycache__/
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
.adf_final*.json
# Claude Code agent worktrees / local scratch (never scanned or committed)
.claude/

View file

@ -45,7 +45,7 @@ note_missing() { echo " [MISSING] $1 — not run. Install: $2" >&2; }
if command -v cfn-lint >/dev/null; then
# Prune generated/vendored trees (cdk.out, node_modules, …): scanning synthesized output is
# wrong and, on CDK repos, explodes the arg list / stalls the scanners.
TPLS="$(scope_paths | xargs -I{} find {} \( -type d \( -name cdk.out -o -name node_modules -o -name .git -o -name .aws-sam -o -name .venv -o -name venv -o -name dist -o -name build \) -prune \) -o \( -type f \( -name '*.yaml' -o -name '*.yml' \) -print \) 2>/dev/null \
TPLS="$(scope_paths | xargs -I{} find {} \( -type d \( -name cdk.out -o -name node_modules -o -name .git -o -name .claude -o -name .aws-sam -o -name .venv -o -name venv -o -name dist -o -name build \) -prune \) -o \( -type f \( -name '*.yaml' -o -name '*.yml' \) -print \) 2>/dev/null \
| xargs -I{} sh -c 'grep -lE "AWSTemplateFormatVersion|Transform: *AWS::Serverless" "{}" 2>/dev/null || true')"
if [ -n "$TPLS" ]; then
# shellcheck disable=SC2086
@ -69,7 +69,7 @@ SCOPE_PATHS="$(scope_paths)"
# --- semgrep (SAST: injection/authz/xss/secrets) ---
if command -v semgrep >/dev/null; then
# shellcheck disable=SC2086
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off --exclude cdk.out --exclude node_modules --exclude .venv --exclude venv --exclude .aws-sam --exclude dist --exclude build $SCOPE_PATHS 2>/dev/null)"; then
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off --exclude cdk.out --exclude node_modules --exclude .claude --exclude .venv --exclude venv --exclude .aws-sam --exclude dist --exclude build $SCOPE_PATHS 2>/dev/null)"; then
NORM="$(echo "$SG" | jq '[.results[] | {
id: ("semgrep-" + (.check_id|split(".")|last) + "-" + (.start.line|tostring)),
title: ((.check_id|split(".")|last) + ": " + ((.extra.message // "")[0:120])),
@ -116,7 +116,7 @@ if command -v checkov >/dev/null; then
# scanning cdk.out/<stack>.template.json, which is the real deploy artifact
# (dropping it would silence genuine S3/IAM IaC findings). asset is anchored to
# cdk.out so a source file literally named asset.* is not also excluded.
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.claude' --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
else RAW="$(checkov -f "$p" -o json --compact --quiet 2>/dev/null || true)"; fi
[ -z "$RAW" ] && continue
FC="$(echo "$RAW" | jq '[ (if type=="array" then .[] else . end).results.failed_checks // [] ] | add // []' 2>/dev/null || echo '[]')"