feat: create machine-level suppressions dir on --global hook install

install-hooks.sh --global now mkdir -p's
${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and
states the convention: machine-level <dir>/<repo-basename>/suppressions.json
is preferred over repo-local .security-review/suppressions.json, with
review.sh merging both when run without --suppressions.
This commit is contained in:
Adam Moussa 2026-07-14 19:05:29 -04:00
parent e061ef8f80
commit 2165312426
No known key found for this signature in database
2 changed files with 9 additions and 0 deletions

View file

@ -40,6 +40,11 @@ The global mode sets `git config --global core.hooksPath ~/.config/git/hooks`. S
its own local `core.hooksPath` overrides the global hook — install per-repo there. See memory
`reference_global_security_review_hook`.
- `--global` also creates the machine-level suppressions dir
(`${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}`): the per-repo file
`<dir>/<repo-basename>/suppressions.json` is preferred by the hooks over repo-local
`.security-review/suppressions.json`, and `review.sh` merges both when run without `--suppressions`.
**Suppressing a false positive.** A written justification is required and is surfaced in the report.
When no `--suppressions FILE` is passed, `review.sh` auto-resolves and **merges** suppressions from
two locations (an explicit `--suppressions` still overrides both):

View file

@ -18,6 +18,7 @@ set -euo pipefail
SRC="$(cd "$(dirname "$0")" && pwd)"
GLOBAL_HOOKS="$HOME/.config/git/hooks"
CLAUDE_DIR="$HOME/.claude"
SUP_DIR="${SH_SECURITY_SUPPRESSIONS_DIR:-$HOME/.config/sea-haven/security-review}"
usage() { grep '^#' "$0" | sed 's/^# \{0,1\}//'; }
@ -40,6 +41,9 @@ case "${1:-}" in
--global)
echo "== Installing Sea Haven security-review hooks globally =="
mkdir -p "$GLOBAL_HOOKS"
mkdir -p "$SUP_DIR"
echo " suppressions: machine-level per-repo file $SUP_DIR/<repo-basename>/suppressions.json is preferred by the hooks over repo-local .security-review/suppressions.json"
echo " suppressions: review.sh merges both locations when run without --suppressions"
# Warn (don't clobber silently) if a different global hooksPath is already set.
CURRENT="$(git config --global --get core.hooksPath || true)"