๐ŸŒฟ headcheck v1.0.2 ยท MIT

Verify the HEAD file of dumb-HTTP git repos is still cloneable โ€” read-only, from the outside, zero dependencies.

The problem

On a dumb-HTTP git server, the post-update hook (git update-server-info) regenerates info/refs but does not protect the bare repo's HEAD file. A broken HEAD (raw SHA instead of a symref, branch deleted, HEAD lost) makes git clone fail with empty repository even though info/refs answers 200 and the landing pages look fine. headcheck catches it before your users do.

What it does

Install (pip)

pip install headcheck @ git+https://mandrilly.com/git/headcheck.git
# macOS venv without system CA bundle:
pip install "headcheck[certs] @ git+https://mandrilly.com/git/headcheck.git"

Usage

headcheck --base https://example.com/git              # discover repos from the index
headcheck --base https://example.com/git --repo mytool
headcheck --base ... --json                           # machine-readable report
headcheck --base ... --quiet                          # verdict line only

Sample output:

[OK ] pdfgen: HEAD -> main @ da08cab
[FAIL] broken-repo: HEAD is not a valid symref (content: 'a1b2c3...')
headcheck FAIL: 1/24 repos broken

Exit codes

CodeMeaning
0all checked repos HEAD-valid and resolvable
1at least one repo broken (clone would fail)
2error (index unreachable, no repos found)

Cron pattern

headcheck --base https://example.com/git --quiet \
  || echo "headcheck exit $?" | mail -s "git HEAD broken" ops@example.com

Tests

Self-contained unittest suite serving a fixture dumb-HTTP layout over a local HTTP server:

python -m unittest test_headcheck    # 6 tests