| # ADR-0014 pre-push security gate. | |
| # | |
| # This repo's `origin` IS the HuggingFace Space (git push builds the live Space), | |
| # so there is no GitHub Actions merge gate. This hook is the enforced check in | |
| # that HF-only deploy model: it runs the shared scan before a push ships code. | |
| # | |
| # Install with: make install-hooks | |
| # | |
| # A developer *can* bypass a local hook (`git push --no-verify`), so this is | |
| # paired with the scheduled unattended scan β it is not as strong as a | |
| # server-side merge gate. Set SECURITY_SCAN_STRICT=1 to fail on skipped stages. | |
| # | |
| # Skip intentionally (e.g. a docs-only push) with: git push --no-verify | |
| set -euo pipefail | |
| # Capture the ref lines git feeds a pre-push hook on stdin BEFORE anything else | |
| # can consume them β git-lfs's chained hook below needs them to know which LFS | |
| # objects to upload. Installing this hook REPLACED git-lfs's own pre-push hook, | |
| # which silently broke every push containing a new LFS-tracked file (HF rejects | |
| # with "LFS pointer pointed to a file that does not exist" until a manual | |
| # `git lfs push <remote> main`). Found deploying b4a5c90. | |
| hook_stdin="$(cat || true)" | |
| repo_root="$(git rev-parse --show-toplevel)" | |
| echo "[pre-push] running ADR-0014 security scan (git push --no-verify to skip)β¦" | |
| if bash "$repo_root/scripts/security_scan.sh" < /dev/null; then | |
| echo "[pre-push] security scan clean β proceeding." | |
| else | |
| echo "[pre-push] security scan reported findings β push blocked." >&2 | |
| echo "[pre-push] triage security/ artifacts, or 'git push --no-verify' to override." >&2 | |
| exit 1 | |
| fi | |
| # Chain git-lfs's pre-push (after the scan, so a blocked push uploads nothing). | |
| # Replays the captured ref lines; "$@" is the remote name + URL git passed us. | |
| if command -v git-lfs >/dev/null 2>&1; then | |
| if ! printf '%s' "$hook_stdin" | git lfs pre-push "$@"; then | |
| echo "[pre-push] git lfs pre-push failed β push blocked (LFS objects not uploaded)." >&2 | |
| exit 1 | |
| fi | |
| else | |
| echo "[pre-push] WARNING: git-lfs not installed β a push with new LFS-tracked files" >&2 | |
| echo "[pre-push] will be rejected by the remote until 'git lfs push' is run manually." >&2 | |
| fi | |
| exit 0 | |