Decomposer produced 9 stories under docs/work/2026-05-14-ci- security-and-supply-chain/, ordered to land the schema foundation first and the cross-referencing content (reviewer prompt, guide) last: 01 - trace schema extensions (socketRisk + lastRevalidated) 02 - Socket integration (skill + CI) 03 - Renovate adoption 04 - major-bump re-evaluation flow 05 - trace revalidation workflow 06 - CodeQL + audit signatures 07 - gitleaks pre-commit 08 - reviewer prompt update 09 - CI security guide + docs Also fixes a one-char status typo in the PRD frontmatter (\`appoved\` -> \`approved\`) that landed with the decompose run. Anchored by ADR-023 + the approved PRD at docs/work/prds/2026-05-14-ci-security-and-supply-chain.prd.md. Sequencing: depends on stories 01/02/04/06 of the in-flight library-evaluation epic landing first.
2.6 KiB
2.6 KiB
id, epic, title, type, status, feature, depends-on, blocks
| id | epic | title | type | status | feature | depends-on | blocks | |
|---|---|---|---|---|---|---|---|---|
| 07-gitleaks-precommit | 2026-05-14-ci-security-and-supply-chain | Gitleaks pre-commit hook | technical-story | todo | tooling |
|
Goal
Add gitleaks protect --staged --redact as a step in .husky/pre-commit and ship a .gitleaks.toml allowlist that covers test-fixture patterns in __seeds__/**, so a commit containing a known secret pattern is blocked locally before it reaches the remote.
Why
Developer accidents (pasting tokens into config, seeding test fixtures with real-looking keys) are the most common secret-leak vector. A pre-commit hook stops the leak at the earliest possible point — before the secret is ever pushed. GitHub native push protection is the second line of defense (documented in Story 09's guide); the hook is the first. The __seeds__/** allowlist prevents false positives from test fixtures that deliberately use token-shaped strings as dummy data.
Done when
.husky/pre-commithas agitleaks protect --staged --redactstep that runs before the existing state-sync guard (or after — order between guards doesn't matter, both must run)..gitleaks.tomlexists at repo root with at minimum one allowlist rule scoping__seeds__/**test fixtures (usingpathsorallowlist.pathsdepending on the gitleaks version).- A smoke test (bash script or vitest) pipes a staged commit containing a Stripe-style test key (
sk_test_...) through the hook and asserts non-zero exit code. The smoke test is documented in the story's Done-when but may live as a manual verification step given gitleaks requires a binary; include instructions indocs/guides/ci-security.md(Story 09) for consumers to verify locally. pnpm typecheck && pnpm lint && pnpm test && pnpm conformance && pnpm fallow:audit && pnpm coverage:diffall pass.
In scope
.husky/pre-commit— newgitleaksstep..gitleaks.toml— allowlist config.
Out of scope
- Installing
gitleaksas a project devDependency — consumers install it via their OS package manager orbrew; the hook exits gracefully with a warning ifgitleaksis not found in$PATH(to avoid blocking developers who haven't installed it yet, while still enforcing for those who have). - GitHub native push protection configuration — consumer-facing instruction deferred to Story 09's guide.
Tasks
- Add
gitleaks protect --staged --redactstep to.husky/pre-commit(exit-gracefully ifgitleaksnot in$PATH); create.gitleaks.tomlat repo root with__seeds__/**allowlist for test-fixture patterns; one commit, all gates pass.