- Updated file tracking to include `.dev.vars` alongside `.env` and `.env.*`. - Improved pre-commit hook to block plaintext secret files, including `.dev.vars`. - Added `clear` command to remove plaintext secret files from the current directory and workspaces. - Enhanced tests to cover new functionality for `.dev.vars` and the `clear` command. - Updated documentation to reflect changes in tracked files and command usage.
12 lines
477 B
Bash
Executable file
12 lines
477 B
Bash
Executable file
#!/usr/bin/env bash
|
|
# Pre-commit hook for the secrets repo.
|
|
# Rejects staged files matching .env patterns without .age extension.
|
|
# This is a safety net, not a security boundary (--no-verify bypasses it).
|
|
|
|
BLOCKED=$(git diff --cached --name-only | grep -E '\.(env|dev\.vars)' | grep -v '\.age$' || true)
|
|
if [ -n "$BLOCKED" ]; then
|
|
echo "ERROR: Plaintext secret files staged for commit:"
|
|
echo "$BLOCKED"
|
|
echo "Only .age (encrypted) files should be committed."
|
|
exit 1
|
|
fi
|