The global pre-push hook, the /sh-security-review prompt, and finding.schema.json previously lived only in ~/.config/git and ~/.claude (untracked) — unreproducible. Source them here: add hooks/pre-push, rewrite install-hooks.sh with a --global mode (lays down both hooks, sets core.hooksPath, links skill+schema into ~/.claude) and a per-repo mode. Align pre-commit with pre-push (honor skip marker + suppressions). Add semgrep p/javascript so the scanners cover the org's Node/.NET repos.
19 lines
1.2 KiB
Bash
Executable file
19 lines
1.2 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Sea Haven security-review pre-commit hook: FAST deterministic scanners only (sub-30s).
|
|
# The full agentic review is the on-demand /sh-security-review slash command — run that before pushing.
|
|
# Honors the same skip/suppress controls as pre-push so a suppressed FP doesn't block the commit.
|
|
# --no-verify skips this local fast feedback; the pre-push hook + nightly VM sweep are the backstop.
|
|
set -uo pipefail
|
|
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0
|
|
[ -f "$REPO_ROOT/.security-review-skip" ] && exit 0
|
|
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
|
|
if [ ! -f "$REVIEW_SH" ]; then
|
|
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2
|
|
exit 0
|
|
fi
|
|
# Nothing staged -> nothing to do.
|
|
git diff --cached --name-only --diff-filter=ACM | grep -q . || exit 0
|
|
SUP=()
|
|
[ -f "$REPO_ROOT/.security-review/suppressions.json" ] && SUP=(--suppressions "$REPO_ROOT/.security-review/suppressions.json")
|
|
# ${SUP[@]+"${SUP[@]}"} = bash-3.2-safe expansion of a possibly-empty array under set -u.
|
|
exec bash "$REVIEW_SH" --scanners-only ${SUP[@]+"${SUP[@]}"} "$REPO_ROOT"
|