Set up server-side commit hooks in git to run your checks. Don't allow binaries to be run from user-writable locations.