Skip to content

guardrails: hook-disable paths block-no-verify does not see (git alias, Set-Item env:HUSKY/LEFTHOOK) #5186

Description

@kyle-sexton

Problem

A bypass review of #4817 found commands that skip commit hooks and pass block-no-verify on current main, with no opt-in token set:

  • git config alias.c 'commit -n'; git c -m x: an alias defined in the same command hides -n.
  • Set-Item env:HUSKY 0; git commit -m x, Set-Item env:LEFTHOOK 0; git commit -m x, si env:LEFTHOOK 0; ...: hook managers disabled through PowerShell env assignment. (Main already blocks [Environment]::SetEnvironmentVariable('LEFTHOOK','0') and bash LEFTHOOK=0 git commit.)

Expected

These block like --no-verify: a same-command git config alias.* whose value contains a no-verify flag, and PowerShell env assignment (Set-Item/si/$env: = ...) of HUSKY, LEFTHOOK or other hook-manager disable variables the guard already knows for bash.

Acceptance criteria

  • block-no-verify.test.sh cases for each command above, blocked.
  • The PowerShell env-assignment forms share the list of hook-disable variables the bash path uses.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions