From 216531242657ee5c926132a97ce90044c2c082ea Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 14 Jul 2026 19:05:29 -0400 Subject: [PATCH] feat: create machine-level suppressions dir on --global hook install install-hooks.sh --global now mkdir -p's ${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review} and states the convention: machine-level //suppressions.json is preferred over repo-local .security-review/suppressions.json, with review.sh merging both when run without --suppressions. --- README.md | 5 +++++ install-hooks.sh | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/README.md b/README.md index 1ae68e7..45d1eaa 100644 --- a/README.md +++ b/README.md @@ -40,6 +40,11 @@ The global mode sets `git config --global core.hooksPath ~/.config/git/hooks`. S its own local `core.hooksPath` overrides the global hook — install per-repo there. See memory `reference_global_security_review_hook`. +- `--global` also creates the machine-level suppressions dir + (`${SH_SECURITY_SUPPRESSIONS_DIR:-~/.config/sea-haven/security-review}`): the per-repo file + `//suppressions.json` is preferred by the hooks over repo-local + `.security-review/suppressions.json`, and `review.sh` merges both when run without `--suppressions`. + **Suppressing a false positive.** A written justification is required and is surfaced in the report. When no `--suppressions FILE` is passed, `review.sh` auto-resolves and **merges** suppressions from two locations (an explicit `--suppressions` still overrides both): diff --git a/install-hooks.sh b/install-hooks.sh index 6a10a78..42ed933 100755 --- a/install-hooks.sh +++ b/install-hooks.sh @@ -18,6 +18,7 @@ set -euo pipefail SRC="$(cd "$(dirname "$0")" && pwd)" GLOBAL_HOOKS="$HOME/.config/git/hooks" CLAUDE_DIR="$HOME/.claude" +SUP_DIR="${SH_SECURITY_SUPPRESSIONS_DIR:-$HOME/.config/sea-haven/security-review}" usage() { grep '^#' "$0" | sed 's/^# \{0,1\}//'; } @@ -40,6 +41,9 @@ case "${1:-}" in --global) echo "== Installing Sea Haven security-review hooks globally ==" mkdir -p "$GLOBAL_HOOKS" + mkdir -p "$SUP_DIR" + echo " suppressions: machine-level per-repo file $SUP_DIR//suppressions.json is preferred by the hooks over repo-local .security-review/suppressions.json" + echo " suppressions: review.sh merges both locations when run without --suppressions" # Warn (don't clobber silently) if a different global hooksPath is already set. CURRENT="$(git config --global --get core.hooksPath || true)"