Files
openconcho/.husky/pre-push

9 lines
289 B
Plaintext
Raw Normal View History

chore(hooks): pre-push gate, secret scan, pr:evidence drafter Phase A of the quality-gate rollout — local + pre-push gates that stop slop before it leaves the laptop. Preventative controls, per the architect playbook. - .husky/pre-commit — adds scripts/secret-scan.sh as the first check before the existing Biome format/lint. Blocks the commit when a likely secret is found in staged additions. Existing Biome behaviour is preserved. - .husky/pre-push (new) — runs `pnpm check` (lint + typecheck + test) before the branch leaves the laptop. Mirrors the `check` job in .github/workflows/ci.yml so PR-blocking issues surface locally first. Bypassable for genuine emergencies with `git push --no-verify`. - scripts/secret-scan.sh (new) — regex scan over staged additions for the common accidents: AWS keys, Anthropic/OpenAI/GitHub/Slack/Google/ Stripe tokens, JWTs, PEM private key blocks, hardcoded password literals. Validated against synthetic leaks of each type. No external tool dependency — pure bash + grep, runs in <100ms typical. - scripts/pr-evidence.sh (new) — drafts a PR_BODY.md from the diff vs origin/main: file lists (added/modified/deleted), commit summaries, and the QA checklist. Flags screenshots as REQUIRED when the diff touches packages/web/src/{components,routes} or packages/desktop. Wired as `pnpm pr:evidence` so it runs from anywhere in the workspace. - .gitignore — adds PR_BODY.md so drafts don't get committed by accident. Pre-commit stays fast (<2s typical). Heavy checks (typecheck, full test run) live in pre-push.
2026-05-24 18:29:13 +01:00
#!/bin/sh
# Pre-push gate — runs the full quality check before the branch leaves the
# laptop. Mirrors the `check` job in .github/workflows/ci.yml.
#
# Bypass for genuine emergencies with: git push --no-verify
echo "→ Running pre-push checks (lint + typecheck + test)…"
pnpm check