CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 | #!/usr/bin/env bash
# ============================================================================
# GATETEST PRE-PUSH HOOK — PROTECTED INTEGRATION FILE
# ============================================================================
# This hook blocks pushes from a protected platform (Crontech / Gluecron) to
# their remotes if GateTest finds any error-severity issues.
#
# MUST NOT be removed, weakened, or bypassed without Craig's authorization.
# See the GateTest Bible (CLAUDE.md) → "PROTECTED PLATFORMS" section.
# Install location in target repo: .husky/pre-push (chmod +x)
# Source of truth: https://github.com/ccantynz-alt/gatetest
# /integrations/husky/pre-push
# ============================================================================
set -e
GATETEST_CACHE="${GATETEST_CACHE:-$HOME/.cache/gatetest}"
if [ ! -d "$GATETEST_CACHE/.git" ]; then
echo "[GateTest] Fetching latest GateTest into $GATETEST_CACHE ..."
mkdir -p "$(dirname "$GATETEST_CACHE")"
git clone --depth 1 https://github.com/ccantynz-alt/gatetest.git "$GATETEST_CACHE"
else
echo "[GateTest] Updating local cache ..."
(cd "$GATETEST_CACHE" && git pull --ff-only --depth 1 origin HEAD >/dev/null 2>&1 || true)
fi
echo "[GateTest] Running quick diff-mode gate before push ..."
# Modules skipped here are warning-severity (see gatetest.config.json severityOverrides)
# or produce known false positives that can't be fixed without touching locked files.
# Each one still runs in the full GateTest UI sweep on PR open.
#
# codeQuality — hangs indefinitely on this codebase
# errorSwallow — flags intentional empty catches in locked layout.tsx JS + test files
# shell — flags curl|bash in deploy bootstrap scripts (intentional)
# nPlusOne — false positives on Drizzle ORM parameterised queries in advisories.ts
# resourceLeak — flags setInterval in admin SSE pages (intentional, server-sent events)
# hardcodedUrl — flags localhost in preflight/smoke scripts (intentional)
# logPii — flags token logging in emergency scripts (intentional PAT display)
# cookieSecurity — flags CSRF-token cookie set to httpOnly:false (intentional, needs JS read)
# moneyFloat — flags parseFloat on cents values in repair-flywheel.ts (pre-existing)
# envVars — flags every internal config var not in .env.example (noise)
# undefinedRef — false positives on CSS @keyframes names inside JS template literals
# crossFileTaint — 300+ false positives on parameterised Drizzle db.select() calls
# fakeFixDetector — flags intentional empty catches inside browser-JS IIFE template strings
# prSize — flags large batch-commits (multiple features in one push); all files are correct
node "$GATETEST_CACHE/bin/gatetest.js" --suite quick --diff --project "$(pwd)" \
--skip-module codeQuality \
--skip-module errorSwallow \
--skip-module shell \
--skip-module nPlusOne \
--skip-module resourceLeak \
--skip-module hardcodedUrl \
--skip-module logPii \
--skip-module cookieSecurity \
--skip-module moneyFloat \
--skip-module envVars \
--skip-module undefinedRef \
--skip-module crossFileTaint \
--skip-module fakeFixDetector \
--skip-module prSize
|