Files
baya-monorepo/.githooks

Git hooks

Repo-managed git hooks (they live in version control, unlike .git/hooks).

Enable (once per clone)

git config core.hooksPath .githooks

pre-commit — secret scan

A fast, dependency-free backstop against a credential leaking into a file that shouldn't hold one (refinement-phase-5). It rejects a commit that stages:

  • the retired hardcoded admin password qw123321, anywhere,
  • private-key material or an AWS access-key id, anywhere,
  • the deployment's SQL Server host 87.107.152.16 outside the declared config files,
  • a real connection-string password in any appsettings*.json outside the declared config files (elsewhere only the SET_VIA_USER_SECRETS_OR_ENV placeholder is allowed).

Declared config files. The pre-launch demo deployment configures itself from committed files rather than a secret store (DEPLOY.md), so a short allow-list — appsettings.Development.json, docker-compose.yml, telegram-otp-bot/.env.example, DEPLOY.md — is exempt from the last two checks. The list is maintained in the declared_config function in the hook and is the honest record of where the repo's secrets are. Shrink it, never grow it: once real users exist, those values must be rotated and moved out of git.

It scans only staged additions, so it is quick. It is not a replacement for a full scanner (gitleaks / trufflehog) in CI — it is the local first line of defence.

Bypass a false positive with git commit --no-verify (use sparingly, and only when you are certain the flagged line is not a secret).