Skip to main content

commit-shield 🛡️

PyPI version Python versions License: MIT Tests good first issues Hacktoberfest

Fast, zero-dependency Git commit message and staged file linter.

Enforces Conventional Commits standards and guards against accidental commits of secrets (.env, .pem, id_rsa) or oversized files (> 10MB).


⚡ Why commit-shield?

  • Zero dependencies: Written in pure standard Python. Instant install, lightweight, no massive node_modules or heavy binary dependencies.
  • Fast: Runs in milliseconds during git commit.
  • Pre-commit ready: Seamless drop-in integration with the popular pre-commit framework.
  • Dual protection: Validates both commit message formatting AND safeguards against accidentally committed credentials/blobs.

📦 Installation

pip install commit-shield

Or install from source:

git clone https://github.com/lui01212/commit-guard.git
cd commit-guard
pip install -e .

🚀 Usage

1. Check Commit Messages

Validate commit message strings directly:

# Valid commit message -> exit code 0
commit-guard check-msg -m "feat(auth): add google oauth2 login provider"

# Invalid commit message -> exit code 1 with actionable errors
commit-guard check-msg -m "fixed stuff"

Output:

[commit-guard] Commit message validation failed:
  - Header does not follow Conventional Commits format: '<type>(<scope>): <description>'.
    Received: 'fixed stuff'
    Allowed types: build, chore, ci, docs, feat, fix, perf, refactor, revert, style, test

2. Check Staged Files (Secrets & Large Blobs)

# Checks all currently staged files in git
commit-guard check-files --strict

3. One-Click Git Hook Setup (No pre-commit framework needed)

Install the hook directly into your local .git/hooks/commit-msg:

commit-guard install

🔧 Integration with pre-commit

Add this to your .pre-commit-config.yaml:

repos:
  - repo: https://github.com/lui01212/commit-guard
    rev: v0.2.0
    hooks:
      - id: commit-guard-msg
      - id: commit-guard-files

⚙️ Configuration

commit-guard works zero-config out of the box, but can be fully customized via .commit-guard.toml or [tool.commit-guard] in pyproject.toml:

# .commit-guard.toml
max_header_len = 72
require_scope = false
skip_merge_commits = true
max_size_mb = 10.0

# Add extra sensitive patterns to protect
extra_sensitive_patterns = ["*.secret", "*_token.json"]

# Allowlist false-positives
allowlist = ["*.example", "*.sample", "*.template"]

See .commit-guard.toml.example for all available options.


📋 Allowed Commit Types

Type Purpose
feat A new feature
fix A bug fix
docs Documentation only changes
style Formatting, missing semi-colons, white-space changes
refactor Code restructuring without fixing bugs or adding features
perf Performance improvement
test Adding missing tests or correcting existing tests
build Changes that affect the build system or dependencies
ci Changes to CI configuration files and scripts
chore Maintenance tasks, tooling updates
revert Reverting a previous commit

🤝 Contributing

Contributions are warmly welcomed! We have plenty of beginner-friendly tasks:

  • Adding custom pattern checks.
  • Expanding sensitive file extension detections.
  • Adding localized error messages (Vietnamese, Spanish, etc.).

Please see CONTRIBUTING.md for details on how to get started.


📄 License

MIT License © 2026 lui01212

Release files for commit-shield 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for commit-shield 0.2.0
File Size Uploaded
commit_shield-0.2.0.tar.gz 30.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for commit-shield 0.2.0
File Interpreter ABI Platform
commit_shield-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 50.7 kB

Release files / commit_shield-0.2.0.tar.gz

Download URL commit_shield-0.2.0.tar.gz
Size 30.8 kB
Tags Source
SHA-256 checksum
How to use checksums
8057b7eb552551eac28679969922e17f916a4d11d2d9ee2d6947a7c4d8a3517c
BLAKE2b-256 checksum
How to use checksums
ef92629a0a7dd5b40bc4acea46979ee60778e1d266af02b270bd58eea443fc8e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / commit_shield-0.2.0-py3-none-any.whl

Download URL commit_shield-0.2.0-py3-none-any.whl
Size 19.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
53b949517f240c8e8731507b912fe9b033c05fa0210bde24705cecfad204f587
BLAKE2b-256 checksum
How to use checksums
0ee40466d58c5adfc1862d5b2073e1cc7a8fd2db607612ec773db970c1368fe1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.0

2 release files

This release

0.2.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page