This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/security-review/hooks/pre-commit
Adam Moussa 7e5ce1f5b2 Add security-review gate (review.sh + scanners + pre-commit hook)
Trigger-agnostic pure-code gate that merges deterministic-scanner findings
(semgrep/gitleaks/checkov/cfn-lint/pip-audit) with agent findings from
/sh-security-review, dedups, applies justification-required suppressions, and
makes the block decision (exit 1 on confirmed critical/high). Phase 2 of the
Sea Haven security-review agent; Path B (CI/headless) wiring lands in Phase 3.
2026-06-15 15:52:15 -04:00

14 lines
783 B
Bash
Executable file

#!/usr/bin/env bash
# Sea Haven security-review pre-commit hook: FAST deterministic scanners only (sub-30s).
# The full agentic review is the on-demand /sh-security-review slash command — run that before pushing.
# CI re-runs review.sh as the unbypassable backstop, so --no-verify here only skips local fast feedback.
set -euo pipefail
REPO_ROOT="$(git rev-parse --show-toplevel)"
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
if [ ! -f "$REVIEW_SH" ]; then
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2
exit 0
fi
# Nothing staged -> nothing to do.
git diff --cached --name-only --diff-filter=ACM | grep -q . || exit 0
bash "$REVIEW_SH" --scanners-only "$REPO_ROOT"