Skip to main content

Goal

Before each commit, scan the files you are about to commit. If they contain open source that scanoss.json does not approve, stop the commit and show what the scan found. This catches copied code before it reaches a pull request.

When to use it

  • Developers on your team paste code from the internet or from AI coding tools, and you want feedback before review.
  • You want the same rule as your pull request check, but earlier.
The hook gives developers early feedback, but it cannot enforce anything. Anyone can skip it with git commit --no-verify. Keep the pull request check as the gate.

Prerequisites

  • scanoss-cli on the developer’s PATH (see Quickstart)
  • An API key stored once on the workstation:
  • jq and bash
  • Network access to the SCANOSS API (or your own deployment) at commit time
  • scanoss/unapproved.jq committed to the repository (see Approve components)

The hook

Save this as .git/hooks/pre-commit in your repository and make it executable (chmod +x .git/hooks/pre-commit).

What each step does

  1. Export the staged files. git diff --cached lists the staged files. git checkout-index writes the staged version of each one into a temporary directory, not the version in your working tree. The hook checks exactly what the commit will contain, even if you staged only part of your changes.
  2. Settings. The temporary directory has no scanoss.json, so the hook passes the repository’s file with --settings. Paths keep their layout, so path-scoped rules still match.
  3. Scan. scanoss-cli fingerprints the files locally and uploads only the fingerprints to the API. Your source code does not leave the machine. The scan uses the key stored by scanoss-cli config set.
  4. Gate. The hook runs the same jq check as the pull request recipe. Any detected component without a bom.identify approval stops the commit.

What the output means

Each line names the matched component and the staged files where the scan found it. To continue:
  • If you meant to include it, add a bom.identify rule to scanoss.json and stage that change too. See Approve components with scanoss.json.
  • If you did not, remove the code and stage again.

How it fails

Git aborts the commit when the hook exits with a non-zero code: If you prefer the hook to warn instead of block when the API cannot be reached (for example, on a train), change the exit 1 in step 3 to exit 0. The pull request check still applies.

Share the hook with your team

Git does not commit files in .git/hooks. To share the hook, commit it to the repository, for example as scripts/hooks/pre-commit, and ask each developer to point Git at that directory once:
If your team already uses a hook manager, call the same script from it.

Keep it fast

The hook scans only the staged files, so most commits finish in seconds. For large commits, such as an initial import, skip the hook with --no-verify and rely on the pull request check.