fix(hkv,rul): add 3 verified hook events; correct globs-rule wording
HKV: add Setup, UserPromptExpansion, PostToolBatch to VALID_EVENTS, verified live against code.claude.com/docs/en/hooks.md (2026-06-19). A valid hook using one of these was wrongly flagged "will never fire" — a user could delete a working hook. Made the "(N total)" hint dynamic so it can't drift again. Flagged the unverified kebab 'post-session' in a comment (an existing test depends on it; follow-up check needed). RUL: reword the globs finding. Only `paths:` is documented; whether CC ever read `globs` is unverified, so the old "deprecated/legacy" framing overclaimed (Verifiseringsplikt). New wording steers to the documented `paths:` field. Updated the coupled fix-engine title match and the humanizer entry (which also carried the "field was renamed" overclaim). Suite 950 -> 954 (badge bumped). self-audit A/A, scanner count 13. No version bump — these land in the pending v5.4.1 patch. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ter3E2JSi1Khgmuf2kady8
This commit is contained in:
parent
5a270704fd
commit
b6a62d7699
7 changed files with 84 additions and 19 deletions
|
|
@ -148,6 +148,56 @@ describe('HKV scanner — CC 2.1.152/2.1.169 hook events (Batch 1 false-positive
|
|||
});
|
||||
});
|
||||
|
||||
describe('HKV scanner — Setup/UserPromptExpansion/PostToolBatch events (Batch 2 false-positive fix)', () => {
|
||||
// Three more events verified live against code.claude.com/docs/en/hooks.md
|
||||
// (2026-06-19): Setup (session-level), UserPromptExpansion (per-turn),
|
||||
// PostToolBatch (agentic loop). Same hermetic temp-fixture pattern — the
|
||||
// path-guard blocks committing settings.json/hooks.json fixtures.
|
||||
let tmpRoot;
|
||||
let result;
|
||||
|
||||
const NEW_EVENTS = ['Setup', 'UserPromptExpansion', 'PostToolBatch'];
|
||||
|
||||
beforeEach(async () => {
|
||||
resetCounter();
|
||||
tmpRoot = await mkdtemp(join(tmpdir(), 'ca-hkv-events2-'));
|
||||
await mkdir(join(tmpRoot, '.claude'), { recursive: true });
|
||||
const settings = {
|
||||
hooks: {
|
||||
// 'echo …' commands skip the script-existence check, isolating
|
||||
// event-name validation.
|
||||
Setup: [{ hooks: [{ type: 'command', command: 'echo setup' }] }],
|
||||
UserPromptExpansion: [{ hooks: [{ type: 'command', command: 'echo expand' }] }],
|
||||
PostToolBatch: [{ hooks: [{ type: 'command', command: 'echo batch' }] }],
|
||||
},
|
||||
};
|
||||
await writeFile(
|
||||
join(tmpRoot, '.claude', 'settings.json'),
|
||||
JSON.stringify(settings, null, 2) + '\n',
|
||||
'utf8',
|
||||
);
|
||||
const discovery = await discoverConfigFiles(tmpRoot);
|
||||
result = await scan(tmpRoot, discovery);
|
||||
});
|
||||
|
||||
afterEach(async () => {
|
||||
if (tmpRoot) await rm(tmpRoot, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
for (const event of NEW_EVENTS) {
|
||||
it(`does NOT flag "${event}" as an unknown hook event`, () => {
|
||||
const unknown = result.findings.find(f =>
|
||||
f.title === 'Unknown hook event' && f.evidence === event);
|
||||
assert.equal(unknown, undefined, `${event} should be in VALID_EVENTS`);
|
||||
});
|
||||
}
|
||||
|
||||
it('produces zero findings for a valid Setup + UserPromptExpansion + PostToolBatch config', () => {
|
||||
assert.equal(result.findings.length, 0,
|
||||
`expected clean scan; got: ${result.findings.map(f => `${f.title}:${f.evidence || ''}`).join(' | ')}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('HKV scanner — empty project', () => {
|
||||
let result;
|
||||
beforeEach(async () => {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue