From 202a7a9e1d59cb6fbd2f9aea4b8e184c4d8378d4 Mon Sep 17 00:00:00 2001 From: bussyjd Date: Wed, 13 Aug 2025 21:10:26 +0400 Subject: [PATCH 1/2] misc: improve security checks --- .githooks/pre-commit | 39 +++++++++++++++++++++++++++++++++++++++ .gitignore | 17 +++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100755 .githooks/pre-commit diff --git a/.githooks/pre-commit b/.githooks/pre-commit new file mode 100755 index 00000000..c2068c1b --- /dev/null +++ b/.githooks/pre-commit @@ -0,0 +1,39 @@ +#!/bin/bash + +# Pre-commit hook to prevent sensitive data leaks + +set -e + +RED='\033[0;31m' +GREEN='\033[0;32m' +NC='\033[0m' + +echo "🔍 Checking for sensitive files..." + +# Critical patterns to block +blocked_patterns=( + "canary-.*/" + "node[0-9]+/" + "cluster-lock\.json" + "validator_keys/" + "keystore-.*\.(json|txt)" + "charon-enr-private-key" + ".*private.*key" +) + +found_issues=0 +for file in $(git diff --cached --name-only); do + for pattern in "${blocked_patterns[@]}"; do + if echo "$file" | grep -qE "$pattern"; then + echo -e "${RED}❌ BLOCKED: $file (matched: $pattern)${NC}" + found_issues=1 + fi + done +done + +if [ $found_issues -eq 0 ]; then + echo -e "${GREEN}✅ No sensitive files detected${NC}" +else + echo -e "${RED}Remove sensitive files before committing!${NC}" + exit 1 +fi \ No newline at end of file diff --git a/.gitignore b/.gitignore index ca609158..0d30271e 100644 --- a/.gitignore +++ b/.gitignore @@ -12,3 +12,20 @@ data/ .idea .charon prometheus/prometheus.yml + +# Cluster data and keys +**/canary-*/ +**/node[0-9]*/ +**/cluster-lock.json +**/validator_keys/ +**/keystore-*.json +**/keystore-*.txt +**/charon-enr-private-key + +# Dependencies +**/node_modules/ + +# Local test files +test-*.yaml +demo-*.yaml +*.log From 1ecbdea8bedd6144e9d81d9ae45237775e129a60 Mon Sep 17 00:00:00 2001 From: bussyjd Date: Wed, 13 Aug 2025 21:11:56 +0400 Subject: [PATCH 2/2] chore: cleanup --- .gitignore | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/.gitignore b/.gitignore index 0d30271e..b5e89010 100644 --- a/.gitignore +++ b/.gitignore @@ -20,12 +20,4 @@ prometheus/prometheus.yml **/validator_keys/ **/keystore-*.json **/keystore-*.txt -**/charon-enr-private-key - -# Dependencies -**/node_modules/ - -# Local test files -test-*.yaml -demo-*.yaml -*.log +**/charon-enr-private-key \ No newline at end of file