fix(Git Node): Disable git hooks by default (#21797)

Co-authored-by: yehorkardash <yehor.kardash@n8n.io>
This commit is contained in:
RomanDavydchuk
2025-11-14 16:55:46 +02:00
committed by GitHub
co-authored by yehorkardash
parent 24895a9a69
commit 4dd853b2d5
4 changed files with 39 additions and 0 deletions
@@ -55,4 +55,10 @@ export class SecurityConfig {
/** Whether to allow access to AWS system credentials, e.g. in awsAssumeRole credentials */
@Env('N8N_AWS_SYSTEM_CREDENTIALS_ACCESS_ENABLED')
awsSystemCredentialsAccess: boolean = false;
/**
* Whether to enable hooks (like pre-commit hooks) for the Git node.
*/
@Env('N8N_GIT_NODE_ENABLE_HOOKS')
enableGitNodeHooks: boolean = false;
}
+1
View File
@@ -317,6 +317,7 @@ describe('GlobalConfig', () => {
disableWebhookHtmlSandboxing: false,
disableBareRepos: false,
awsSystemCredentialsAccess: false,
enableGitNodeHooks: false,
},
executions: {
mode: 'regular',
@@ -302,6 +302,11 @@ export class Git implements INodeType {
gitConfig.push('safe.bareRepository=explicit');
}
const enableHooks = securityConfig.enableGitNodeHooks;
if (!enableHooks) {
gitConfig.push('core.hooksPath=/dev/null');
}
const gitOptions: Partial<SimpleGitOptions> = {
baseDir: repositoryPath,
config: gitConfig,
@@ -30,6 +30,7 @@ describe('Git Node', () => {
});
securityConfig = mock<SecurityConfig>({
disableBareRepos: false,
enableGitNodeHooks: true,
});
Container.set(DeploymentConfig, deploymentConfig);
Container.set(SecurityConfig, securityConfig);
@@ -114,4 +115,30 @@ describe('Git Node', () => {
);
});
});
describe('Hooks Configuration', () => {
it('should add core.hooksPath=/dev/null when enableGitNodeHooks is false', async () => {
securityConfig.enableGitNodeHooks = false;
await gitNode.execute.call(executeFunctions);
expect(mockSimpleGit).toHaveBeenCalledWith(
expect.objectContaining({
config: ['core.hooksPath=/dev/null'],
}),
);
});
it('should not add core.hooksPath=/dev/null when enableGitNodeHooks is true', async () => {
securityConfig.enableGitNodeHooks = true;
await gitNode.execute.call(executeFunctions);
expect(mockSimpleGit).toHaveBeenCalledWith(
expect.objectContaining({
config: [],
}),
);
});
});
});