ci: gate pushes on a gitleaks scan of the outgoing commits
No repo here scanned for committed credentials. The hook is self-contained rather than delegating to a Makefile, because this repo has none and a hook reaching into a sibling repo breaks the moment this one is cloned elsewhere. Scans the outgoing range rather than full history: history carries settled findings — test fixtures, vendored third-party code — and a gate that fails on something unfixable gets bypassed within a week. Setting core.hooksPath means pql init must replant its replication shims into .githooks, which is why they are gitignored here alongside the tracked pre-push. Same layout pql itself uses. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -80,3 +80,11 @@ webber-sandbox/.current_template
|
||||
.claude/settings.local.json
|
||||
.pql/*
|
||||
!.pql/changelog/
|
||||
|
||||
# pql shims planted by `pql init` into the dir core.hooksPath points at.
|
||||
# Per-clone: each embeds the absolute path of the pql binary that planted it.
|
||||
# Only .githooks/pre-push is shared.
|
||||
.githooks/pre-commit
|
||||
.githooks/post-merge
|
||||
.githooks/post-checkout
|
||||
.githooks/post-rewrite
|
||||
|
||||
Reference in New Issue
Block a user