Pre-receive hooks
Using pre-receive hooks
Pre-receive hooks are custom scripts that Git runs server-side whenever new commits are pushed to a repository. They inspect incoming changes before acceptance, enforcing standards and rules without requiring users to install pre-commit hooks. They're available on self-hosted platforms such as:
- GitHub Enterprise Server
- GitLab Self-Managed
- Bitbucket Data Center
NOTE: Implementation details vary by provider, be sure to consult your provider's documentation for specific setup instructions.
To run as a pre-receive hook, the scanner must be invoked via bash script using the git scanner. The --bare option is required since the full repository isn't available in the context of a pre-receive hook.
The trufflehog binary must be executable and in the $PATH variable for the Git instance. The example below should work in most environments, though file naming conventions differ: some platforms accept arbitrary script names, e.g. trufflehog_hook.sh, while GitLab requires the script name to reflect the hook type, e.g. pre_receive.
NOTE: trufflehog in the script below refers to the open-source scanner.
Pre-receive script for TruffleHog
#!/bin/bash
/trufflehog --no-update git --bare file://. --only-verified --fail