#!/bin/bash # Activate the repo's tracked git hooks for this clone. # # Hooks live under hooks/ (version-controlled) and are wired via core.hooksPath, # so every machine gets the same hooks after running this once. # # This script used to GENERATE .git/hooks/pre-commit from a heredoc. That made the # running hook a copy, and a copy drifts: measured 2026-09-19, the installed hook on # one machine was an older revision than this script emitted, having lost the Linux # gitleaks install hint. core.hooksPath runs the tracked file itself, so the hook # that runs and the hook in git history cannot disagree. # # core.hooksPath is LOCAL config and is never cloned, which is why this step exists # at all: a fresh clone has hooks/ and no active gate until someone runs this. set -e cd "$(git rev-parse --show-toplevel)" git config core.hooksPath hooks chmod +x hooks/* 2>/dev/null || true # Prove the setting took rather than trusting that it did: a hook that was never # activated behaves exactly like one that has nothing to report. active="$(git config --get core.hooksPath || true)" if [ "$active" != "hooks" ]; then echo "❌ core.hooksPath is '$active', not 'hooks' — the gate is NOT active." >&2 exit 1 fi # A hook left behind by the old copy-based install would be shadowed by # core.hooksPath and never run again, so say so rather than leaving a decoy. if [ -e .git/hooks/pre-commit ]; then echo "⚠️ .git/hooks/pre-commit still exists and is now INERT (core.hooksPath wins)." echo " It is a leftover from the old copy-based install; remove it:" echo " rm .git/hooks/pre-commit" fi echo "✅ core.hooksPath set to hooks/ — tracked hooks are now active" echo " (pre-commit secret scan via gitleaks)"