CLAUDE.md documents commands, the spec-first workflow, the functional-core rule and a do-not list. A Claude Code Stop hook blocks finishing while typecheck or unit tests fail. Permissions deny reading env files, hook bypass flags, hard resets and recursive deletes, and ask before CI edits or any push. Husky pre-commit now also typechecks and runs unit tests; pre-push runs coverage and the mutation gate when src/domain changed. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
42 lines
904 B
JSON
42 lines
904 B
JSON
{
|
|
"permissions": {
|
|
"deny": [
|
|
"Read(./.env)",
|
|
"Read(./.env.*)",
|
|
"Read(./apps/web/.env)",
|
|
"Read(./apps/web/.env.*)",
|
|
"Edit(./.env)",
|
|
"Edit(./.env.*)",
|
|
"Bash(git push --force*)",
|
|
"Bash(git push -f*)",
|
|
"Bash(git push * main*)",
|
|
"Bash(git push * master*)",
|
|
"Bash(git commit *--no-verify*)",
|
|
"Bash(git commit * -n *)",
|
|
"Bash(git reset --hard*)",
|
|
"Bash(git clean*)",
|
|
"Bash(rm -rf*)"
|
|
],
|
|
"ask": [
|
|
"Edit(./.gitea/workflows/**)",
|
|
"Write(./.gitea/workflows/**)",
|
|
"Edit(./Dockerfile*)",
|
|
"Edit(./docker-compose*)",
|
|
"Bash(git push*)"
|
|
]
|
|
},
|
|
"hooks": {
|
|
"Stop": [
|
|
{
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/verify.sh",
|
|
"timeout": 180
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|