A company is using AWS CodeCommit for source code management. The security team has identified a risk where developers might accidentally commit sensitive information (e.g., private keys, passwords) into repositories. They need an automated solution to prevent such commits before they become part of the repository history. Which CodeCommit feature or integration can help enforce this preventative measure?
- AImplement Git hooks (pre-receive) on the CodeCommit repository.
- BUse AWS CodeGuru Reviewer for security analysis after the commit.
- CConfigure AWS Config rules to detect sensitive information after commit.
- DEnable S3 bucket policies on the CodeCommit repository's underlying storage.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement Git hooks (pre-receive) on the CodeCommit repository.
Git hooks, specifically pre-receive hooks, are server-side scripts that execute before a push is accepted into the repository. Implementing a pre-receive hook in CodeCommit can automatically scan incoming commits for sensitive patterns (e.g., regex for private keys) and reject the push if detected, thereby preventing sensitive information from ever entering the repository history.
Why the other options are wrong
- B. CodeGuru Reviewer analyzes code *after* it has been committed, providing recommendations but not preventing the initial commit of sensitive data.
- C. AWS Config rules are detective; they identify non-compliance *after* it occurs, which is too late for preventing sensitive data in commit history.
- D. CodeCommit repositories do not expose their underlying S3 storage for direct policy modification by users.
CodeCommit Git Hooks
Scripts that CodeCommit automatically executes before or after events such as a push, commit, or merge. Pre-receive hooks are server-side and run before a push is accepted, allowing for validation and rejection.
- Automate tasks during Git operations.
- Pre-receive hooks can prevent pushes.
- Useful for enforcing coding standards and security policies.
Memory trick: Git hooks are the 'gatekeepers' preventing secrets from entering the code vault.