Fix pre-commit hook by use git-agnostic file-based checking #1918
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description:
This fixes gitleaks invocations via pre-commit when there are no changed to-be-committed (i.e., via
pre-commit run --files
orpre-commit run --all-files
). Currently, these will pass even if there would be gitleaks findings becausegitleaks git
checks the diff only.When called via pre-commit framework, gitleaks does not need to git-aware because the framework already detects which files need to be checked (either the diff when a commit range or changes that are about-to-be-committed are checked, or the files passed to the
--files
command line argument).Fixes #1409.
Checklist: