Skip to content

feat(security): scan commit messages in the client-name watchlist gate - #220

Merged
RevealUIStudio merged 1 commit into
testfrom
feat/commit-message-client-name-gate-84c1
Oct 5, 2026
Merged

RevealUIStudio merged 1 commit into
testfrom
feat/commit-message-client-name-gate-84c1

Conversation

@RevealUIStudio

Copy link
Copy Markdown
Owner

Summary

Layer B file scan still defaults to paths. Scrubbing a pull request title does not stop a buyer or company slug from landing in the commit subject or body, so the watchlist gate now scans commit messages before merge.

  • scripts/check-no-client-names.sh --commits [range] and SCAN_COMMIT_MESSAGES=1 match watchlist terms case-insensitively against subject and body. Hits look like commit:<sha>:subject or commit:<sha>:body.
  • Default range is origin/$GITHUB_BASE_REF..HEAD (else origin/test..HEAD). Two-dot selects commits reachable from HEAD that are not on the base. A three-dot range also selects commits that exist only on the base. Pass an explicit range to override.
  • R-003 class residuals (a slug already in merged history) stay forward-only. This does not rewrite history.
  • CLIENT_NAME_PR_TITLE is scanned only in commit mode (the squash or merge subject).
  • scripts/hooks/commit-msg-client-names.sh is an opt-in commit-msg helper (husky, lefthook, or .git/hooks). Bootstrap does not install it.
  • On pull_request, .github/workflows/check-no-client-names.yml fetches full history and runs base_sha..HEAD plus the pull request title. Push events still only file-scan.
  • No watchlist: WARN and exit 0, including commit mode. CLIENT_NAME_WATCHLIST_REQUIRED stays unset in CI.

How to activate

Local (never commit the real list):

  1. Copy templates/client-name-watchlist.example to .client-name-watchlist.local (gitignored).
  2. Replace the placeholders with operator-local terms.
  3. File scan: bash scripts/check-no-client-names.sh
  4. Commit scan: bash scripts/check-no-client-names.sh --commits 'origin/test..HEAD'
  5. Optional hook: ln -sfn ../../scripts/hooks/commit-msg-client-names.sh .git/hooks/commit-msg

Placeholder dry run (do not substitute real terms):

CLIENT_NAME_PATTERNS='buyer_example|agency_client_example' \
  bash scripts/check-no-client-names.sh --commits 'origin/test..HEAD'

CI secret (do not put term text in the workflow):

  1. Store the watchlist in a GitHub Actions secret. This PR does not name or create that secret.
  2. Write the secret to a file outside the checkout (for example $RUNNER_TEMP/client-name-watchlist) with mode 0600.
  3. Export CLIENT_NAME_WATCHLIST_FILE to that path on both the file-scan step and the pull-request commit-scan step.
  4. Leave CLIENT_NAME_WATCHLIST_REQUIRED unset so a missing file stays inactive (exit 0). Set it to 1 only if a missing file should fail the job (exit 2).

Tests

bash tests/test-check-no-client-names.sh (placeholder patterns only).

Open in Web Open in Cursor 

Extend the watchlist gate so pull request CI and an opt-in commit-msg
hook match subjects and bodies before merge. File scan stays the
default, and the gate stays inactive until a local watchlist or secret
is mounted.

Co-authored-by: Joshua Vaughn <founder@revealui.com>

@RevealUIStudio RevealUIStudio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security soft review (Layer B commit-msg gate)

PASS P0=0 P1=0. Draft → test only. No promote. No history rewrite.

Closes inventory gap #6 surface: watchlist gate now scans commit subject/body (and PR title in commit mode) without embedding terms. File-scan default unchanged; inactive without watchlist. Two-dot range leaves R-003 accepted base-only history alone.

Soft note (P2): activate CI secret / local watchlist separately; bootstrap does not install the commit-msg hook.

sec-review:approved for merge-to-test when CI green and owner/FDE undrafts.

@RevealUIStudio
RevealUIStudio marked this pull request as ready for review October 5, 2026 14:23
@RevealUIStudio
RevealUIStudio merged commit 982c640 into test Oct 5, 2026
31 checks passed
@RevealUIStudio
RevealUIStudio deleted the feat/commit-message-client-name-gate-84c1 branch October 5, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants