refinement phase 5
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
# Git hooks
|
||||
|
||||
Repo-managed git hooks (they live in version control, unlike `.git/hooks`).
|
||||
|
||||
## Enable (once per clone)
|
||||
|
||||
```bash
|
||||
git config core.hooksPath .githooks
|
||||
```
|
||||
|
||||
## `pre-commit` — secret scan
|
||||
|
||||
A fast, dependency-free backstop for the root `CLAUDE.md` rule **"Never commit secrets"**
|
||||
(refinement-phase-5). It rejects a commit that stages:
|
||||
|
||||
- the historically-leaked SQL Server host `87.107.152.16`,
|
||||
- the retired hardcoded admin password `qw123321`,
|
||||
- a **real** connection-string password in any `appsettings*.json` (only the `SET_VIA_USER_SECRETS_OR_ENV`
|
||||
placeholder is allowed — real values belong in user-secrets / environment variables),
|
||||
- private-key material or an AWS access-key id, anywhere.
|
||||
|
||||
It scans only staged additions, so it is quick. It is **not** a replacement for a full scanner
|
||||
(gitleaks / trufflehog) in CI — it is the local first line of defence.
|
||||
|
||||
Bypass a false positive with `git commit --no-verify` (use sparingly, and only when you are certain the
|
||||
flagged line is not a secret).
|
||||
Reference in New Issue
Block a user