Goal
Before each commit, scan the files you are about to commit. If they contain open source thatscanoss.json does not approve, stop the commit and show what the scan found. This catches copied
code before it reaches a pull request.
When to use it
- Developers on your team paste code from the internet or from AI coding tools, and you want feedback before review.
- You want the same rule as your pull request check, but earlier.
git commit --no-verify. Keep the pull request check as the gate.
Prerequisites
-
scanoss-cli on the developer’s
PATH(see Quickstart) -
An API key stored once on the workstation:
-
jqandbash - Network access to the SCANOSS API (or your own deployment) at commit time
-
scanoss/unapproved.jqcommitted to the repository (see Approve components)
The hook
Save this as.git/hooks/pre-commit in your repository and make it executable
(chmod +x .git/hooks/pre-commit).
What each step does
- Export the staged files.
git diff --cachedlists the staged files.git checkout-indexwrites the staged version of each one into a temporary directory, not the version in your working tree. The hook checks exactly what the commit will contain, even if you staged only part of your changes. - Settings. The temporary directory has no
scanoss.json, so the hook passes the repository’s file with--settings. Paths keep their layout, so path-scoped rules still match. - Scan. scanoss-cli fingerprints the files locally and uploads only the fingerprints to the
API. Your source code does not leave the machine. The scan uses the key stored by
scanoss-cli config set. - Gate. The hook runs the same
jqcheck as the pull request recipe. Any detected component without abom.identifyapproval stops the commit.
What the output means
- If you meant to include it, add a
bom.identifyrule toscanoss.jsonand stage that change too. See Approve components with scanoss.json. - If you did not, remove the code and stage again.
How it fails
Git aborts the commit when the hook exits with a non-zero code:
If you prefer the hook to warn instead of block when the API cannot be reached (for example, on
a train), change the
exit 1 in step 3 to exit 0. The pull request check still applies.
Share the hook with your team
Git does not commit files in.git/hooks. To share the hook, commit it to the repository, for
example as scripts/hooks/pre-commit, and ask each developer to point Git at that directory once:
Keep it fast
The hook scans only the staged files, so most commits finish in seconds. For large commits, such as an initial import, skip the hook with--no-verify and rely on the pull request check.