Problem
A bypass review of #4817 found commands that skip commit hooks and pass block-no-verify on current main, with no opt-in token set:
git config alias.c 'commit -n'; git c -m x: an alias defined in the same command hides -n.
Set-Item env:HUSKY 0; git commit -m x, Set-Item env:LEFTHOOK 0; git commit -m x, si env:LEFTHOOK 0; ...: hook managers disabled through PowerShell env assignment. (Main already blocks [Environment]::SetEnvironmentVariable('LEFTHOOK','0') and bash LEFTHOOK=0 git commit.)
Expected
These block like --no-verify: a same-command git config alias.* whose value contains a no-verify flag, and PowerShell env assignment (Set-Item/si/$env: = ...) of HUSKY, LEFTHOOK or other hook-manager disable variables the guard already knows for bash.
Acceptance criteria
block-no-verify.test.sh cases for each command above, blocked.
- The PowerShell env-assignment forms share the list of hook-disable variables the bash path uses.
Related
Problem
A bypass review of #4817 found commands that skip commit hooks and pass
block-no-verifyon current main, with no opt-in token set:git config alias.c 'commit -n'; git c -m x: an alias defined in the same command hides-n.Set-Item env:HUSKY 0; git commit -m x,Set-Item env:LEFTHOOK 0; git commit -m x,si env:LEFTHOOK 0; ...: hook managers disabled through PowerShell env assignment. (Main already blocks[Environment]::SetEnvironmentVariable('LEFTHOOK','0')and bashLEFTHOOK=0 git commit.)Expected
These block like
--no-verify: a same-commandgit config alias.*whose value contains a no-verify flag, and PowerShell env assignment (Set-Item/si/$env:= ...) ofHUSKY,LEFTHOOKor other hook-manager disable variables the guard already knows for bash.Acceptance criteria
block-no-verify.test.shcases for each command above, blocked.Related