- New scripts/work/bump-updated-timestamps.mjs stamps the `updated:`
frontmatter field to the current ISO 8601 UTC timestamp on every
staged docs/work/**/*.md file. Idempotent; adds the field after
`created:` if missing.
- .husky/pre-commit invokes the bump script as step 2 (before
rebuild-state) so _state.json sees the fresh timestamp.
- Backfill all existing work docs (4 PRDs + 3 epics + 21 stories):
* created: promoted from \`YYYY-MM-DD\` -> ISO timestamp using
git log --diff-filter=A on each file (first-commit date for
stories that had no \`created:\` line, midnight UTC for PRDs
and epics that had date-only created).
* updated: added from \`git log -1 --format=%aI\` on each file
(last-commit timestamp); will be re-stamped to "now" by the
pre-commit hook on this commit.
Stories that had no \`created:\` line now get one.
32 lines
1.3 KiB
Bash
Executable File
32 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env sh
|
|
|
|
# Pre-commit gates — fast checks only. Slow checks (full conformance, full
|
|
# test, full typecheck) stay in CI.
|
|
|
|
# 1. lint-staged: format + lint staged files
|
|
pnpm exec lint-staged || exit 1
|
|
|
|
# 2. Stamp the `updated:` frontmatter field on every staged docs/work/ md file.
|
|
node scripts/work/bump-updated-timestamps.mjs || exit 1
|
|
|
|
# 3. If any docs/work/ markdown is staged, regenerate _state.json + re-stage it
|
|
if git diff --cached --name-only | grep -qE '^docs/work/.*\.md$'; then
|
|
pnpm work rebuild-state
|
|
git add docs/work/_state.json
|
|
fi
|
|
|
|
# 3. Run the state-sync guard: refuses to commit if _state.json is
|
|
# staged but doesn't match what rebuild-state would produce. Catches the case
|
|
# where someone hand-edits _state.json without going through rebuild-state.
|
|
node scripts/work/state-sync-guard.mjs || exit 1
|
|
|
|
# 4. Check library decision traces for new runtime deps in feature/core packages.
|
|
node scripts/library-decisions/check.mjs || exit 1
|
|
|
|
# 5. Scan staged changes for secrets (skip gracefully if gitleaks is not installed).
|
|
if command -v gitleaks > /dev/null 2>&1; then
|
|
gitleaks protect --staged --redact || exit 1
|
|
else
|
|
echo "gitleaks not found in \$PATH — skipping secret scan (install via brew install gitleaks or https://github.com/gitleaks/gitleaks)"
|
|
fi
|