fix(scripts/githooks): prevent agents from bypassing git hooks (#22825)

Agents hit short shell timeouts on `git commit` (~13s) before
`make pre-commit` finishes (~20s warm), then disable hooks via
`git config core.hooksPath /dev/null`. This bypasses all local checks
and, because it writes to shared `.git/config`, silently disables hooks
for every other worktree too.

Add explicit timing guidance to AGENTS.md, and write worktree-scoped
`core.hooksPath` in post-checkout, pre-commit, and pre-push hooks to
make the bypass ineffective.
This commit is contained in:
Mathias Fredriksson
2026-03-09 12:51:44 +02:00
committed by GitHub
parent a48e4a43e2
commit dd34e3d3c2
4 changed files with 45 additions and 9 deletions
+4
View File
@@ -19,4 +19,8 @@ set -euo pipefail
cd "$(git rev-parse --show-toplevel)"
unset GIT_DIR
# In linked worktrees, set worktree-scoped hooksPath to override shared config.
if [[ "$(git rev-parse --git-dir)" != "$(git rev-parse --git-common-dir)" ]]; then
git config --worktree core.hooksPath scripts/githooks
fi
exec make pre-push