commit-shield 🛡️
Fast, zero-dependency Git commit message and staged file linter.
Enforces Conventional Commits standards and guards against accidental commits of secrets (.env, .pem, id_rsa) or oversized files (> 10MB).
⚡ Why commit-shield?
- Zero dependencies: Written in pure standard Python. Instant install, lightweight, no massive node_modules or heavy binary dependencies.
- Fast: Runs in milliseconds during
git commit. - Pre-commit ready: Seamless drop-in integration with the popular
pre-commitframework. - Dual protection: Validates both commit message formatting AND safeguards against accidentally committed credentials/blobs.
📦 Installation
pip install commit-shield
Or install from source:
git clone https://github.com/lui01212/commit-guard.git
cd commit-guard
pip install -e .
🚀 Usage
1. Check Commit Messages
Validate commit message strings directly:
# Valid commit message -> exit code 0
commit-guard check-msg -m "feat(auth): add google oauth2 login provider"
# Invalid commit message -> exit code 1 with actionable errors
commit-guard check-msg -m "fixed stuff"
Output:
[commit-guard] Commit message validation failed:
- Header does not follow Conventional Commits format: '<type>(<scope>): <description>'.
Received: 'fixed stuff'
Allowed types: build, chore, ci, docs, feat, fix, perf, refactor, revert, style, test
2. Check Staged Files (Secrets & Large Blobs)
# Checks all currently staged files in git
commit-guard check-files --strict
3. One-Click Git Hook Setup (No pre-commit framework needed)
Install the hook directly into your local .git/hooks/commit-msg:
commit-guard install
🔧 Integration with pre-commit
Add this to your .pre-commit-config.yaml:
repos:
- repo: https://github.com/lui01212/commit-guard
rev: v0.2.0
hooks:
- id: commit-guard-msg
- id: commit-guard-files
⚙️ Configuration
commit-guard works zero-config out of the box, but can be fully customized via .commit-guard.toml or [tool.commit-guard] in pyproject.toml:
# .commit-guard.toml
max_header_len = 72
require_scope = false
skip_merge_commits = true
max_size_mb = 10.0
# Add extra sensitive patterns to protect
extra_sensitive_patterns = ["*.secret", "*_token.json"]
# Allowlist false-positives
allowlist = ["*.example", "*.sample", "*.template"]
See .commit-guard.toml.example for all available options.
📋 Allowed Commit Types
| Type | Purpose |
|---|---|
feat |
A new feature |
fix |
A bug fix |
docs |
Documentation only changes |
style |
Formatting, missing semi-colons, white-space changes |
refactor |
Code restructuring without fixing bugs or adding features |
perf |
Performance improvement |
test |
Adding missing tests or correcting existing tests |
build |
Changes that affect the build system or dependencies |
ci |
Changes to CI configuration files and scripts |
chore |
Maintenance tasks, tooling updates |
revert |
Reverting a previous commit |
🤝 Contributing
Contributions are warmly welcomed! We have plenty of beginner-friendly tasks:
- Adding custom pattern checks.
- Expanding sensitive file extension detections.
- Adding localized error messages (Vietnamese, Spanish, etc.).
Please see CONTRIBUTING.md for details on how to get started.
📄 License
MIT License © 2026 lui01212
Release files for commit-shield 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| commit_shield-0.3.0.tar.gz | 37.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| commit_shield-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 62.6 kB
Release files / commit_shield-0.3.0.tar.gz
| Download URL | commit_shield-0.3.0.tar.gz |
|---|---|
| Size | 37.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6605c72350c82f60ea5f90158b17be741ca23500b582a3f20d90459fc55e0397
|
|
BLAKE2b-256 checksum How to use checksums |
6f8670db94c8799be0686c58976f334f8f7afe97970418f378f5943e134c587c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / commit_shield-0.3.0-py3-none-any.whl
| Download URL | commit_shield-0.3.0-py3-none-any.whl |
|---|---|
| Size | 25.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b0d59d9b3623a79fec38fe21b8caf0cea76d0131306e0fb0b5f62f452b13f818
|
|
BLAKE2b-256 checksum How to use checksums |
60ecddd2555894090311438fe31664f8f6c0887bb6ae7e5c713183aa6a65448d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log