Commit 6a1bb11
authored
chore(hooks): path-guard + token-guard + .sh→.mts conversion (#628)
Self-landable split from #620. Combines the hook overhaul into one
atomic PR: path-guard infra, token-guard hook, .sh→.mts conversion
of git hooks, and the assorted fleet hooks (private-name-guard,
public-surface-reminder, release-workflow-guard, check-new-deps).
What's included:
Path-guard infra
- .claude/hooks/path-guard/ (hook + tests + segments.mts)
- .claude/skills/path-guard/ (audit-and-fix skill)
- .claude/skills/_shared/path-guard-rule.md (canonical rule)
- scripts/check-paths.mts (the gate)
- .github/paths-allowlist.yml (empty starter, full schema docs)
- .claude/settings.json (wires hook on Edit|Write)
- scripts/check.mts (invokes the gate)
Token-guard hook
- .claude/hooks/token-guard/ (renamed from token-hygiene; word-
boundary match for sensitive env names; ALWAYS_DANGEROUS check
skips when redaction pipeline is present)
.sh → .mts hook conversion (Node 25+)
- .git-hooks/_helpers.mts (was _helpers.sh) — exports
filterAllowedApiKeys + scanners (personal paths, AWS keys,
GitHub tokens, private keys, AI attribution)
- .git-hooks/{commit-msg,pre-commit,pre-push}.mts (were .sh)
- .husky/* shims invoke node directly
Fleet hooks
- .claude/hooks/check-new-deps (npm dep introspection)
- .claude/hooks/private-name-guard
- .claude/hooks/public-surface-reminder
- .claude/hooks/release-workflow-guard
Verification:
pnpm install ✓
pnpm run check --all ✓
pnpm test --all ✓ 565/565 tests pass1 parent d1af774 commit 6a1bb11
44 files changed
Lines changed: 5301 additions & 489 deletions
File tree
- .claude
- hooks
- check-new-deps
- path-guard
- test
- private-name-guard
- public-surface-reminder
- release-workflow-guard
- token-guard
- test
- skills
- path-guard
- reference
- .git-hooks
- .github
- .husky
- scripts
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | | - | |
13 | | - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
14 | 15 | | |
15 | 16 | | |
16 | 17 | | |
| |||
29 | 30 | | |
30 | 31 | | |
31 | 32 | | |
| 33 | + | |
| 34 | + | |
32 | 35 | | |
33 | | - | |
| 36 | + | |
| 37 | + | |
34 | 38 | | |
35 | 39 | | |
36 | 40 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
| 89 | + | |
89 | 90 | | |
90 | 91 | | |
91 | 92 | | |
| |||
159 | 160 | | |
160 | 161 | | |
161 | 162 | | |
162 | | - | |
163 | | - | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
164 | 180 | | |
165 | | - | |
| 181 | + | |
166 | 182 | | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
167 | 196 | | |
168 | 197 | | |
169 | 198 | | |
170 | 199 | | |
171 | 200 | | |
172 | 201 | | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
| 202 | + | |
179 | 203 | | |
180 | 204 | | |
181 | 205 | | |
| |||
280 | 304 | | |
281 | 305 | | |
282 | 306 | | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | | - | |
289 | | - | |
290 | | - | |
291 | | - | |
292 | | - | |
293 | | - | |
294 | | - | |
295 | | - | |
296 | | - | |
297 | | - | |
298 | 307 | | |
299 | 308 | | |
300 | 309 | | |
| |||
728 | 737 | | |
729 | 738 | | |
730 | 739 | | |
| 740 | + | |
| 741 | + | |
| 742 | + | |
| 743 | + | |
| 744 | + | |
| 745 | + | |
| 746 | + | |
| 747 | + | |
| 748 | + | |
| 749 | + | |
| 750 | + | |
| 751 | + | |
| 752 | + | |
| 753 | + | |
| 754 | + | |
| 755 | + | |
| 756 | + | |
| 757 | + | |
| 758 | + | |
| 759 | + | |
| 760 | + | |
| 761 | + | |
| 762 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
0 commit comments