security-review/hooks/pre-commit
Adam Moussa b2b50804bf
Fix stale review.sh default path in hook templates
The 2026-07-09 directory reorg moved this repo under seahaven/, but the
hook templates' default REVIEW_SH path still pointed at the old
location. Every install-hooks.sh --global run since then re-installed
hooks that fail open ("review.sh not found — skipping gate") on every
push. The live hooks on this machine were re-pointed manually
2026-07-15; this fixes the source so the next install doesn't regress.

Refs: INFRA-107
2026-07-15 19:18:35 -04:00

28 lines
1.7 KiB
Bash
Executable file

#!/usr/bin/env bash
# Sea Haven security-review pre-commit hook: FAST deterministic scanners only (sub-30s).
# The full agentic review is the on-demand /sh-security-review slash command — run that before pushing.
# Honors the same skip/suppress controls as pre-push so a suppressed FP doesn't block the commit.
# --no-verify skips this local fast feedback; the pre-push hook + nightly VM sweep are the backstop.
set -uo pipefail
REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || exit 0
[ -f "$REPO_ROOT/.security-review-skip" ] && exit 0
REVIEW_SH="${SH_REVIEW_SH:-$HOME/Documents/repositories/seahaven/security-review/review.sh}"
if [ ! -f "$REVIEW_SH" ]; then
echo "security-review: review.sh not found at $REVIEW_SH (set SH_REVIEW_SH to override) — skipping" >&2
exit 0
fi
# Nothing staged -> nothing to do.
git diff --cached --name-only --diff-filter=ACM | grep -q . || exit 0
SUP=()
# Suppressions: prefer a MACHINE-LEVEL file kept out of repo history
# (<dir>/<repo-basename>/suppressions.json), else fall back to a repo-local
# .security-review/suppressions.json. Keyed by repo basename — adequate for the
# current single-namespace layout under ~/Documents/repositories.
MACHINE_SUP="${SH_SECURITY_SUPPRESSIONS_DIR:-$HOME/.config/sea-haven/security-review}/$(basename "$REPO_ROOT")/suppressions.json"
if [ -f "$MACHINE_SUP" ]; then
SUP=(--suppressions "$MACHINE_SUP")
elif [ -f "$REPO_ROOT/.security-review/suppressions.json" ]; then
SUP=(--suppressions "$REPO_ROOT/.security-review/suppressions.json")
fi
# ${SUP[@]+"${SUP[@]}"} = bash-3.2-safe expansion of a possibly-empty array under set -u.
exec bash "$REVIEW_SH" --scanners-only ${SUP[@]+"${SUP[@]}"} "$REPO_ROOT"