#!/usr/bin/env bash # Sea Haven security-review pre-commit hook: FAST deterministic scanners only (sub-30s). # The full agentic review is the on-demand /sh-security-review slash command — run that before pushing. # Honors the same skip/suppress controls as pre-push so a suppressed FP doesn't block the commit. # --no-verify skips this local fast feedback; the pre-push hook + nightly VM sweep are the backstop. set -uo pipefail REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0 [ -f "$REPO_ROOT/.security-review-skip" ] && exit 0 REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}" if [ ! -f "$REVIEW_SH" ]; then echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2 exit 0 fi # Nothing staged -> nothing to do. git diff --cached --name-only --diff-filter=ACM | grep -q . || exit 0 SUP=() [ -f "$REPO_ROOT/.security-review/suppressions.json" ] && SUP=(--suppressions "$REPO_ROOT/.security-review/suppressions.json") # ${SUP[@]+"${SUP[@]}"} = bash-3.2-safe expansion of a possibly-empty array under set -u. exec bash "$REVIEW_SH" --scanners-only ${SUP[@]+"${SUP[@]}"} "$REPO_ROOT"