Git hooks
Repo-managed git hooks (they live in version control, unlike .git/hooks).
Enable (once per clone)
git config core.hooksPath .githooks
pre-commit — secret scan
A fast, dependency-free backstop against a credential leaking into a file that shouldn't hold one (refinement-phase-5). It rejects a commit that stages:
- the retired hardcoded admin password
qw123321, anywhere, - private-key material or an AWS access-key id, anywhere,
- the deployment's SQL Server host
87.107.152.16outside the declared config files, - a real connection-string password in any
appsettings*.jsonoutside the declared config files (elsewhere only theSET_VIA_USER_SECRETS_OR_ENVplaceholder is allowed).
Declared config files. The pre-launch demo deployment configures itself from committed files rather
than a secret store (DEPLOY.md), so a short allow-list — appsettings.Development.json,
docker-compose.yml, telegram-otp-bot/.env.example, DEPLOY.md — is exempt from the last two checks.
The list is maintained in the declared_config function in the hook and is the honest record of where the
repo's secrets are. Shrink it, never grow it: once real users exist, those values must be rotated and
moved out of git.
It scans only staged additions, so it is quick. It is not a replacement for a full scanner (gitleaks / trufflehog) in CI — it is the local first line of defence.
Bypass a false positive with git commit --no-verify (use sparingly, and only when you are certain the
flagged line is not a secret).