Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
cycode-pre-pushhooks never scanned anything when installed through the pre-commit framework, which is the setup our docs describe. From 3.13.0 on they printedPassedand let every push through, secrets included.The cause: pre-commit reads git's pre-push stdin itself and never forwards it. It passes the push range to hooks as
PRE_COMMIT_FROM_REF/PRE_COMMIT_TO_REFinstead. The CLI only read stdin, found it empty, and returned without scanning.What changed
commit_range_documents.py,pre_push_command.py): the hook usesPRE_COMMIT_FROM_REF..PRE_COMMIT_TO_REF. When pre-commit omits them because the push includes the root commit (e.g. the first push to an empty remote), it scans all commits. Hand-written.git/hooks/pre-pushhooks keep reading stdin.PRE_COMMIT=1) but gives no push details, the hook exits 1 with a clear error instead of passing. Empty stdin from plain git is still a quiet pass: git sends it on "Everything up-to-date". Tag pushes and branch deletions also still pass (CM-62406).--allbecamefirst..HEAD, which leaves out the root commit, so a first push of a single commit scanned nothing. The root commit's diff was also reversed (R=Trueon top ofdiff-tree --root), so its secrets looked like removed lines and were dropped. This also affectedcommit-historyandpre-receivescans of root commits.always_run: trueandpass_filenames: false.always_run, pre-commit skipped the hook when the push's net change had no files (secret added, then deleted in a later commit).pass_filenames: false, a large push could run the full scan once per filename batch.scan_result.py): commit-range detections come back as<sha>/<path>and never matched their document, so the text printer crashed with'NoneType' object has no attribute 'path'. They now match. A detection whose document still can't be found is printed without a code snippet, never dropped.pre-pushis added toCOMMIT_RANGE_BASED_COMMAND_SCAN_TYPES, likepre-receive. The printer shows the diff line, and secrets on removed lines are ignored.rev: v3.5.0is bumped, and the pre-push behavior and hook flags are documented.Where to start reading
cycode/cli/apps/scan/pre_push/pre_push_command.py→_get_pre_push_commit_range, thenget_pre_commit_framework_push_rangeincommit_range_documents.py.Verification
Unit tests cover the env-var range, fail-closed, quiet-pass cases, root-commit polarity and document matching.
I also ran real
git pushes through pre-commit to a local bare remote, against the real backend:Not changed
soft_fail, so a backend outage still lets the push through.first..HEADfor--all.revis set tov3.25.0, assuming that's the release carrying this fix.Fixes CM-73654
🤖 Generated with Claude Code