build(security-review): prune .claude worktrees from deterministic scanners
Agent worktrees under .claude/worktrees/ are full repo copies; the cfn-lint
find|xargs template scan overflowed ('command line cannot be assembled') and the
pre-push hook fail-closed to BLOCK whenever a worktree was present. Prune .claude
in the cfn-lint find + semgrep/checkov excludes, and gitignore .claude/ so it is
never scanned or committed. Unblocks main-tree pushes during parallel agent work.
This commit is contained in:
parent
9d7d03d6db
commit
b8b84337f3
2 changed files with 6 additions and 3 deletions
3
.gitignore
vendored
3
.gitignore
vendored
|
|
@ -10,3 +10,6 @@ __pycache__/
|
|||
|
||||
# Stray Atlassian Document Format exports left by an unrelated tool — not part of this repo.
|
||||
.adf_final*.json
|
||||
|
||||
# Claude Code agent worktrees / local scratch (never scanned or committed)
|
||||
.claude/
|
||||
|
|
|
|||
|
|
@ -45,7 +45,7 @@ note_missing() { echo " [MISSING] $1 — not run. Install: $2" >&2; }
|
|||
if command -v cfn-lint >/dev/null; then
|
||||
# Prune generated/vendored trees (cdk.out, node_modules, …): scanning synthesized output is
|
||||
# wrong and, on CDK repos, explodes the arg list / stalls the scanners.
|
||||
TPLS="$(scope_paths | xargs -I{} find {} \( -type d \( -name cdk.out -o -name node_modules -o -name .git -o -name .aws-sam -o -name .venv -o -name venv -o -name dist -o -name build \) -prune \) -o \( -type f \( -name '*.yaml' -o -name '*.yml' \) -print \) 2>/dev/null \
|
||||
TPLS="$(scope_paths | xargs -I{} find {} \( -type d \( -name cdk.out -o -name node_modules -o -name .git -o -name .claude -o -name .aws-sam -o -name .venv -o -name venv -o -name dist -o -name build \) -prune \) -o \( -type f \( -name '*.yaml' -o -name '*.yml' \) -print \) 2>/dev/null \
|
||||
| xargs -I{} sh -c 'grep -lE "AWSTemplateFormatVersion|Transform: *AWS::Serverless" "{}" 2>/dev/null || true')"
|
||||
if [ -n "$TPLS" ]; then
|
||||
# shellcheck disable=SC2086
|
||||
|
|
@ -69,7 +69,7 @@ SCOPE_PATHS="$(scope_paths)"
|
|||
# --- semgrep (SAST: injection/authz/xss/secrets) ---
|
||||
if command -v semgrep >/dev/null; then
|
||||
# shellcheck disable=SC2086
|
||||
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off --exclude cdk.out --exclude node_modules --exclude .venv --exclude venv --exclude .aws-sam --exclude dist --exclude build $SCOPE_PATHS 2>/dev/null)"; then
|
||||
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off --exclude cdk.out --exclude node_modules --exclude .claude --exclude .venv --exclude venv --exclude .aws-sam --exclude dist --exclude build $SCOPE_PATHS 2>/dev/null)"; then
|
||||
NORM="$(echo "$SG" | jq '[.results[] | {
|
||||
id: ("semgrep-" + (.check_id|split(".")|last) + "-" + (.start.line|tostring)),
|
||||
title: ((.check_id|split(".")|last) + ": " + ((.extra.message // "")[0:120])),
|
||||
|
|
@ -116,7 +116,7 @@ if command -v checkov >/dev/null; then
|
|||
# scanning cdk.out/<stack>.template.json, which is the real deploy artifact
|
||||
# (dropping it would silence genuine S3/IAM IaC findings). asset is anchored to
|
||||
# cdk.out so a source file literally named asset.* is not also excluded.
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path 'cdk\.out/asset\.' --skip-path node_modules --skip-path '\.claude' --skip-path '\.venv' --skip-path venv --skip-path '\.aws-sam' --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
|
||||
else RAW="$(checkov -f "$p" -o json --compact --quiet 2>/dev/null || true)"; fi
|
||||
[ -z "$RAW" ] && continue
|
||||
FC="$(echo "$RAW" | jq '[ (if type=="array" then .[] else . end).results.failed_checks // [] ] | add // []' 2>/dev/null || echo '[]')"
|
||||
|
|
|
|||
Reference in a new issue