feat: security scanning API + pre-receive hook blocking (#692) #713
Reference in New Issue
Block a user
Delete Branch "feature/secret-scanning-clean"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary\n\n- Security scanning API endpoints for repos (
/security/alerts,/security/scan,/security/config)\n- Pre-receive hook integration to block pushes containing detected secrets\n- Orchestrator service for scan coordination\n\nReplaces #711 (closed due to cross-branch contamination from parallel agent collision).\n\nRef: #692\n\n## Test plan\n- [ ] Verify security scan API returns results\n- [ ] Verify pre-receive hook blocks pushes with known secret patterns\n- [ ] Verify config endpoints work for enabling/disabling scanning\n\nhttps://claude.ai/code/session_011AAFzotGMf3ayvXhEmStCdAdds /repos/{owner}/{repo}/security/* route group for security alert management, scanning, and configuration endpoints. Claude-Session: https://claude.ai/code/session_011AAFzotGMf3ayvXhEmStCd