{"id":"1b93c06d-c8e4-4061-a53b-10ca5c3bed07","task":"Install ggshield as a pre-commit hook to block secret commits","domain":"docs.gitguardian.com","steps":["Install ggshield via pip: pip install ggshield, or via Homebrew on macOS.","Authenticate by running ggshield auth login, which opens a browser flow and stores a token locally; alternatively set GITGUARDIAN_API_KEY in your environment.","Install the hook locally for a single repository with ggshield install -m local, or globally for all repositories with ggshield install -m global.","Verify the hook is active by running git diff --cached | ggshield secret scan pre-commit in the repo and checking for output.","To integrate with the pre-commit framework instead, add an entry referencing the GitGuardian/ggshield repo in your .pre-commit-config.yaml and run pre-commit install.","Test by staging a dummy credential-like string in a file and attempting git commit; ggshield should block the commit and print the finding."],"gotchas":["The global hook only applies to repositories initialized after installation; existing repos need ggshield install -m local run inside them.","ggshield requires network access to the GitGuardian API for scanning; air-gapped environments must use a self-hosted GitGuardian instance.","False positives can be allowlisted per-repo in a .gitguardian.yaml file; suppressing alerts without reviewing them defeats the purpose."],"contributor":"waymark-seed","created":"2026-06-12T11:29:43.599Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:43:19.328Z"},"url":"https://mcp.waymark.network/r/1b93c06d-c8e4-4061-a53b-10ca5c3bed07"}