This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/hooks/pre-push
Adam Moussa a3ab3f5f40 Make security-review hooks and skill installable from the repo
The global pre-push hook, the /sh-security-review prompt, and finding.schema.json
previously lived only in ~/.config/git and ~/.claude (untracked) — unreproducible.
Source them here: add hooks/pre-push, rewrite install-hooks.sh with a --global mode
(lays down both hooks, sets core.hooksPath, links skill+schema into ~/.claude) and a
per-repo mode. Align pre-commit with pre-push (honor skip marker + suppressions). Add
semgrep p/javascript so the scanners cover the org's Node/.NET repos.
2026-06-16 15:00:00 -04:00

26 lines
1.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# Sea Haven global pre-push security gate — fast deterministic scanners (review.sh --scanners-only).
# Installed via install-hooks.sh --global: lays this down at ~/.config/git/hooks/pre-push and sets
# git config --global core.hooksPath ~/.config/git/hooks
# Skip a repo: add a .security-review-skip file at its root. Bypass once: git push --no-verify.
# Deep agentic pass = on-demand /sh-security-review; nightly VM sweep = the backstop.
set -uo pipefail
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0
[ -f "$REPO_ROOT/.security-review-skip" ] && exit 0
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
if [ -f "$REVIEW_SH" ]; then
SUP=()
[ -f "$REPO_ROOT/.security-review/suppressions.json" ] && SUP=(--suppressions "$REPO_ROOT/.security-review/suppressions.json")
echo "security-review: scanning $REPO_ROOT (scanners-only) before push..." >&2
# ${SUP[@]+"${SUP[@]}"} = bash-3.2-safe expansion of a possibly-empty array under set -u.
if ! bash "$REVIEW_SH" --scanners-only ${SUP[@]+"${SUP[@]}"} "$REPO_ROOT"; then
echo "security-review: BLOCKED (confirmed crit/high). Fix it, suppress with justification, or 'git push --no-verify' to override." >&2
exit 1
fi
else
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH) — skipping gate" >&2
fi
# Don't silently disable a repo-local pre-push hook: chain to it if present.
LOCAL_HOOK="$REPO_ROOT/.git/hooks/pre-push"
[ -x "$LOCAL_HOOK" ] && exec "$LOCAL_HOOK" "$@"
exit 0