Trigger-agnostic pure-code gate that merges deterministic-scanner findings (semgrep/gitleaks/checkov/cfn-lint/pip-audit) with agent findings from /sh-security-review, dedups, applies justification-required suppressions, and makes the block decision (exit 1 on confirmed critical/high). Phase 2 of the Sea Haven security-review agent; Path B (CI/headless) wiring lands in Phase 3.
14 lines
783 B
Bash
Executable file
14 lines
783 B
Bash
Executable file
#!/usr/bin/env bash
|
|
# Sea Haven security-review pre-commit hook: FAST deterministic scanners only (sub-30s).
|
|
# The full agentic review is the on-demand /sh-security-review slash command — run that before pushing.
|
|
# CI re-runs review.sh as the unbypassable backstop, so --no-verify here only skips local fast feedback.
|
|
set -euo pipefail
|
|
REPO_ROOT="$(git rev-parse --show-toplevel)"
|
|
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
|
|
if [ ! -f "$REVIEW_SH" ]; then
|
|
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2
|
|
exit 0
|
|
fi
|
|
# Nothing staged -> nothing to do.
|
|
git diff --cached --name-only --diff-filter=ACM | grep -q . || exit 0
|
|
bash "$REVIEW_SH" --scanners-only "$REPO_ROOT"
|