feat(security): scan commit messages in the client-name watchlist gate - #220
Merged
Merged
Conversation
Extend the watchlist gate so pull request CI and an opt-in commit-msg hook match subjects and bodies before merge. File scan stays the default, and the gate stays inactive until a local watchlist or secret is mounted. Co-authored-by: Joshua Vaughn <founder@revealui.com>
RevealUIStudio
commented
Oct 5, 2026
RevealUIStudio
left a comment
Owner
Author
There was a problem hiding this comment.
Security soft review (Layer B commit-msg gate)
PASS P0=0 P1=0. Draft → test only. No promote. No history rewrite.
Closes inventory gap #6 surface: watchlist gate now scans commit subject/body (and PR title in commit mode) without embedding terms. File-scan default unchanged; inactive without watchlist. Two-dot range leaves R-003 accepted base-only history alone.
Soft note (P2): activate CI secret / local watchlist separately; bootstrap does not install the commit-msg hook.
sec-review:approved for merge-to-test when CI green and owner/FDE undrafts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Layer B file scan still defaults to paths. Scrubbing a pull request title does not stop a buyer or company slug from landing in the commit subject or body, so the watchlist gate now scans commit messages before merge.
scripts/check-no-client-names.sh --commits [range]andSCAN_COMMIT_MESSAGES=1match watchlist terms case-insensitively against subject and body. Hits look likecommit:<sha>:subjectorcommit:<sha>:body.origin/$GITHUB_BASE_REF..HEAD(elseorigin/test..HEAD). Two-dot selects commits reachable from HEAD that are not on the base. A three-dot range also selects commits that exist only on the base. Pass an explicit range to override.CLIENT_NAME_PR_TITLEis scanned only in commit mode (the squash or merge subject).scripts/hooks/commit-msg-client-names.shis an opt-in commit-msg helper (husky, lefthook, or.git/hooks). Bootstrap does not install it.pull_request,.github/workflows/check-no-client-names.ymlfetches full history and runsbase_sha..HEADplus the pull request title. Push events still only file-scan.CLIENT_NAME_WATCHLIST_REQUIREDstays unset in CI.How to activate
Local (never commit the real list):
templates/client-name-watchlist.exampleto.client-name-watchlist.local(gitignored).bash scripts/check-no-client-names.shbash scripts/check-no-client-names.sh --commits 'origin/test..HEAD'ln -sfn ../../scripts/hooks/commit-msg-client-names.sh .git/hooks/commit-msgPlaceholder dry run (do not substitute real terms):
CI secret (do not put term text in the workflow):
$RUNNER_TEMP/client-name-watchlist) with mode0600.CLIENT_NAME_WATCHLIST_FILEto that path on both the file-scan step and the pull-request commit-scan step.CLIENT_NAME_WATCHLIST_REQUIREDunset so a missing file stays inactive (exit 0). Set it to1only if a missing file should fail the job (exit 2).Tests
bash tests/test-check-no-client-names.sh(placeholder patterns only).