Trigger-agnostic pure-code gate that merges deterministic-scanner findings (semgrep/gitleaks/checkov/cfn-lint/pip-audit) with agent findings from /sh-security-review, dedups, applies justification-required suppressions, and makes the block decision (exit 1 on confirmed critical/high). Phase 2 of the Sea Haven security-review agent; Path B (CI/headless) wiring lands in Phase 3.
12 lines
659 B
Bash
Executable file
12 lines
659 B
Bash
Executable file
#!/usr/bin/env bash
|
|
# Install the Sea Haven security-review pre-commit hook into a target repo.
|
|
# Usage: install-hooks.sh /path/to/repo
|
|
set -euo pipefail
|
|
REPO="${1:?usage: install-hooks.sh /path/to/repo}"
|
|
SRC="$(cd "$(dirname "$0")" && pwd)/hooks/pre-commit"
|
|
[ -d "$REPO/.git" ] || { echo "not a git repo: $REPO" >&2; exit 1; }
|
|
HOOK="$REPO/.git/hooks/pre-commit"
|
|
if [ -f "$HOOK" ]; then echo "warning: existing pre-commit hook at $HOOK will be overwritten" >&2; fi
|
|
cp "$SRC" "$HOOK"; chmod +x "$HOOK"
|
|
echo "installed security-review pre-commit hook -> $HOOK"
|
|
echo "note: hook runs deterministic scanners only; full review is /sh-security-review (on demand)."
|