fix(hooks): point default review.sh path at the standalone security-review repo

The pre-push/pre-commit hooks defaulted SH_REVIEW_SH to the orchestrator checkout
(orchestrator/security-review/review.sh). With the gate re-homed here, default to
$HOME/Documents/repositories/security-review/review.sh so push-time gating does
not lapse when orchestrator is deprecated. Live global hook re-pointed to match.
This commit is contained in:
Adam Moussa 2026-06-29 11:43:54 -04:00
parent 4c88c01f7b
commit 3cf9bb7652
No known key found for this signature in database
2 changed files with 2 additions and 2 deletions

View file

@ -6,7 +6,7 @@
set -uo pipefail
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0
[ -f "$REPO_ROOT/.security-review-skip" ] && exit 0
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/security-review/review.sh}"
if [ ! -f "$REVIEW_SH" ]; then
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2
exit 0

View file

@ -7,7 +7,7 @@
set -uo pipefail
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0
[ -f "$REPO_ROOT/.security-review-skip" ] && exit 0
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/orchestrator/security-review/review.sh}"
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/security-review/review.sh}"
if [ -f "$REVIEW_SH" ]; then
SUP=()
# Suppressions: prefer a MACHINE-LEVEL file kept out of repo history