Sign inSign up

ogulcanaydogan/secret-scanner

By ogulcanaydogan

•Updated 8 months ago

Scan code for accidentally committed secrets and API keys

Image
0

850

ogulcanaydogan/secret-scanner repository overview

⁠Secret Scanner

Scan files and git repositories for accidentally committed secrets, API keys, and credentials.

⁠Quick Start

docker run -v $(pwd):/code ogulcanaydogan/secret-scanner

⁠Features

  • Detect API keys, tokens, passwords, private keys
  • Git history scanning
  • Custom pattern rules
  • JSON/SARIF output for CI/CD integration
  • Pre-commit hook compatible
  • Allowlist for false positives

⁠Environment Variables

VariableDescriptionDefault
SCAN_DIRDirectory to scan/code
SCAN_GIT_HISTORYScan git historyfalse
OUTPUT_FORMATOutput: cli/json/sarifcli
ALLOWLIST_FILEPath to allowlist file-
FAIL_ON_FOUNDExit code 1 if secrets foundtrue

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:6be411ab2…

Size

19.9 MB

Last updated

8 months ago

docker pull ogulcanaydogan/secret-scanner