Files
go-config/scripts/githooks/pre-commit
Andriy Oblivantsev 78076ee5a9
Lint / Lint (push) Skipped
Release Please / Release Please (push) Skipped
Release / GoReleaser (push) Skipped
Tests / Test (Go 1.22 / ubuntu-latest) (push) Skipped
Tests / Test (Go 1.23 / ubuntu-latest) (push) Skipped
Tests / Test (Go stable / macos-latest) (push) Skipped
Tests / Test (Go stable / ubuntu-latest) (push) Skipped
Tests / Test (Go stable / windows-latest) (push) Skipped
Secret scan / Secret scan (gitleaks) (push) Successful in 4s
Secret scan / Secret scan (gitleaks) (pull_request) Successful in 3s
Tests / Test (Go 1.22 / ubuntu-latest) (pull_request) Successful in 13s
Tests / Test (Go 1.23 / ubuntu-latest) (pull_request) Successful in 15s
Lint / Lint (pull_request) Successful in 43s
Tests / Test (Go stable / ubuntu-latest) (pull_request) Successful in 22s
Tests / Test (Go stable / macos-latest) (pull_request) Canceled after 0s
Tests / Test (Go stable / windows-latest) (pull_request) Canceled after 0s
feat(security): secret-scan via gitleaks in CI + pre-push/pre-commit hooks (#142)
2026-08-23 19:51:09 +01:00

21 lines
601 B
Bash
Executable File

#!/usr/bin/env bash
#
# pre-commit git hook — blocks a commit if staged changes contain a secret.
# Scans only the staged (index) diff with gitleaks (via secret-scan.sh).
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$(readlink -f "${BASH_SOURCE[0]}")")" && pwd)"
ROOT="$(git rev-parse --show-toplevel)"
if [[ "$SCRIPT_DIR" == "$ROOT/scripts/githooks" ]]; then
SCAN="$SCRIPT_DIR/secret-scan.sh"
else
SCAN="$ROOT/scripts/githooks/secret-scan.sh"
fi
if ! "$SCAN" --staged; then
echo "pre-commit: LEAK FOUND in staged changes; commit BLOCKED. Remove the secret first." >&2
exit 1
fi
exit 0