mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 03:23:13 +00:00
Fresh-init copy of the security-review/ subsystem extracted from Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold: CI reusable-workflow callers (ruff + collect), dependency-review, labeler, dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and nightly_sweep.sh/checker_coordinator.sh remain the source of truth. Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry intentional secret-shaped test data that trips the deterministic gate (the documented detector-fixture false positive); no new logic is introduced.
24 lines
544 B
Bash
Executable file
24 lines
544 B
Bash
Executable file
#!/bin/sh
|
|
#
|
|
# An example hook script to make use of push options.
|
|
# The example simply echoes all push options that start with 'echoback='
|
|
# and rejects all pushes when the "reject" push option is used.
|
|
#
|
|
# To enable this hook, rename this file to "pre-receive".
|
|
|
|
if test -n "$GIT_PUSH_OPTION_COUNT"
|
|
then
|
|
i=0
|
|
while test "$i" -lt "$GIT_PUSH_OPTION_COUNT"
|
|
do
|
|
eval "value=\$GIT_PUSH_OPTION_$i"
|
|
case "$value" in
|
|
echoback=*)
|
|
echo "echo from the pre-receive-hook: ${value#*=}" >&2
|
|
;;
|
|
reject)
|
|
exit 1
|
|
esac
|
|
i=$((i + 1))
|
|
done
|
|
fi
|