feat(security): secret-scan via gitleaks in CI + pre-push/pre-commit hooks (#142)
Release Please / Release Please (push) Skipped
Release / GoReleaser (push) Skipped
Tests / Secret scan (gitleaks) (push) Skipped
Tests / Test (Go 1.25) (push) Skipped
Tests / Test (Go stable) (push) Skipped
Tests / Secret scan (gitleaks) (pull_request) Successful in 4s
Tests / Test (Go 1.25) (pull_request) Successful in 48s
Tests / Test (Go stable) (pull_request) Successful in 51s

This commit is contained in:
Andriy Oblivantsev
2026-08-23 19:51:06 +01:00
parent 20a09530cd
commit 9ead554f5c
5 changed files with 199 additions and 0 deletions
+26
View File
@@ -0,0 +1,26 @@
#!/usr/bin/env bash
#
# install.sh — symlinks the shared githooks (pre-push, pre-commit) into .git/hooks
# for this repository. Safe to run repeatedly.
#
# Usage:
# ./scripts/githooks/install.sh
set -euo pipefail
ROOT="$(git rev-parse --show-toplevel)"
SRC="$ROOT/scripts/githooks"
HOOKS="$ROOT/.git/hooks"
mkdir -p "$HOOKS"
chmod +x "$SRC"/secret-scan.sh "$SRC"/pre-push "$SRC"/pre-commit
for h in pre-push pre-commit; do
if [[ -e "$HOOKS/$h" ]] && [[ ! -L "$HOOKS/$h" ]]; then
echo "error: $HOOKS/$h already exists and is not a symlink; remove it first" >&2
exit 1
fi
ln -sfn "$SRC/$h" "$HOOKS/$h"
echo "installed $h -> $SRC/$h"
done
echo "githooks installed for $(basename "$ROOT")"