Quality Gate
Automated quality enforcement with two hooks:
Stop Hook — Code Quality
Fires on every session stop. Runs JavaScript/TypeScript checks on changed files:
| Check | Tool | Severity |
|---|---|---|
| Types | tsc --noEmit |
BLOCK |
| Lint | eslint |
BLOCK on errors, WARN on warnings |
| Format | prettier --check |
WARN |
| Tests | jest |
BLOCK |
| Dead code | knip (unused exports, deps, files) |
WARN |
| Type coverage | type-coverage (>80% threshold) |
WARN |
| Circular deps | madge --circular |
WARN |
| TODO/FIXME | grep scanner | WARN |
Behavior:
- Missing required tools (tsc, eslint, prettier, jest) = FAIL with install command
- Missing optional tools (knip, type-coverage, madge) = WARN with install suggestion
- Retry limiter: allows stop after 3 consecutive failures
PreToolUse Hook — Security Scan
Intercepts git push commands. Runs 4 scanners in sequence:
semgrep — SAST scan on changed files with
--config=auto- Critical/High findings = BLOCK push
- Medium findings = WARN
- Claude should auto-fix findings before retrying
gitleaks — scans commits being pushed for leaked secrets
- Any secret found = BLOCK push
trivy — filesystem vulnerability, secret, and misconfig scan
- Critical vulns = BLOCK push
- High vulns = WARN
SonarQube (optional) — checks quality gate status if configured
- Requires
SONARQUBE_URLandSONARQUBE_TOKENenv vars, plussonar-project.properties - Skipped silently if
SONARQUBE_TOKENis not set - Failed quality gate = BLOCK push
- Requires
Configuration
| Env Var | Default | Purpose |
|---|---|---|
CLAUDE_QUALITY_GATE |
1 |
Enable/disable quality gate |
CLAUDE_QUALITY_GATE_MAX_RETRIES |
3 |
Max retry attempts before allowing stop |
SONARQUBE_URL |
https://sonarqube.internal |
SonarQube server URL |
SONARQUBE_TOKEN |
(none) | SonarQube auth token |
CLAUDE_NOTIFY_DISCORD |
0 |
Send Discord notifications |
DISCORD_WEBHOOK_URL |
(none) | Discord webhook for notifications |
Commands
/quality run— Run checks manually/quality status— View gate status and recent results/quality config— See active checks and tool availability