Git Hooks Setup
一键配置 Git Hooks,标准化团队开发流程。
Overview
自动生成 pre-commit / commit-msg / pre-push hook 配置,包含代码格式化、commit message 校验、敏感信息检查。支持 husky 和原生 git hooks 两种方案。
When to Use
- User wants to set up git hooks
- User mentions pre-commit or commit message conventions
- User wants to automate lint/format checks
- User inputs
/git-hooks-setup - User wants to enforce pre-push checks (tests, lint)
- User wants to prevent pushing broken code
- User wants to standardize team commit message format
- User wants to add secret scanning before commit
- User wants to auto-format code on every commit
When NOT to Use:
- User only wants to view current git hooks configuration
- User wants CI-based checks (no local hooks needed)
- User's project already has a complete hooks setup
- User wants to run hooks on specific files only (use lint-staged directly)
- User wants to hook into Git events other than pre-commit/commit-msg/push
Core Pattern
Step 1: 检测项目环境
Step 2: 选择方案
Step 3: 生成配置
方案 A: Husky
生成 .husky/pre-commit(执行 lint-staged)和 .husky/commit-msg(执行 commitlint),注意 commitlint 需加 --no 前缀避免交互式安装。
生成 lint-staged 配置(写入 package.json):
生成 .husky/pre-push(可选,push 前跑测试):
方案 B: 原生 git hooks
Step 4: 配置 Commit Message 规范
将 templates/commitlint.config.js 复制到项目根目录(commitlint.config.js)。该配置基于 @commitlint/config-conventional,校验 commit message 格式:
同步安装 commitlint 依赖:
Step 5: 添加敏感信息检查
⚠️ 不要用
grep "password|secret|token"这种关键字扫描 —— 业务代码里出现 "token"/"secret" 字样是常态,会大面积误报导致提交被频繁拦截。
推荐使用 gitleaks(专门做密钥扫描,内置熵检测 + 允许列表,误报率低):
如果确实无法安装 gitleaks,退而求其次也要避免整词误报 —— 只匹配高置信度模式(如私钥块、AWS 密钥格式),不要匹配 token/secret/password 这类业务常用词:


