add pre-push quality gate

.githooks/pre-push runs make push-check, which aggregates the gates
that must pass before a push lands: Go lint, test, test-race, build,
test-integration, vuln, plus Flutter app-analyze and app-test. App-
side targets gracefully noop until Flutter is scaffolded, so the
gate is usable today without waiting on the app bootstrap.

Hooks are versioned under .githooks/ rather than the usual local
.git/hooks so the gate travels with the repo. `make hooks` wires
them up by pointing git core.hooksPath at the tracked directory —
one-time setup, documented in CLAUDE.md alongside `make tools`.

The hook prepends $GOBIN/$HOME/go/bin to PATH before invoking make,
so govulncheck / goimports / golangci-lint installed via `make tools`
resolve even when the user hasn't added that directory to their
login PATH.

The git-commit skill already forbids --no-verify, which is what keeps
this gate meaningful: "the hook is slow" is a reason to fix the slow
test, not to bypass the gate.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-20 22:14:12 +02:00
co-authored by Claude Opus 4.7
parent c39c2df6f5
commit 0de5f06f43
2 changed files with 19 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
#!/usr/bin/env bash
# Pre-push gate. Blocks the push if any quality check fails.
#
# Install: `make hooks` (points git core.hooksPath at .githooks/).
# Bypass: never. If this runs slowly, fix the slow test; don't reach
# for --no-verify (git-commit skill forbids it).
set -euo pipefail
cd "$(git rev-parse --show-toplevel)"
# `make tools` installs Go-installed binaries into $HOME/go/bin (or
# $GOBIN if set). Users routinely forget to put that on PATH, so the
# hook prepends it here to avoid spurious "command not found" failures
# for govulncheck / goimports / golangci-lint.
export PATH="${GOBIN:-$HOME/go/bin}:$PATH"
echo "==> pre-push: make push-check"
make push-check