Sign inSign up

punksecurity/secret-magpie

By punksecurity

•Updated 9 months ago

Image
0

10K+

punksecurity/secret-magpie repository overview

Maintenance Maintaner Lines of Code Vulnerabilities Bugs

          ____              __   _____                      _ __       
         / __ \__  ______  / /__/ ___/___  _______  _______(_) /___  __
        / /_/ / / / / __ \/ //_/\__ \/ _ \/ ___/ / / / ___/ / __/ / / /
       / ____/ /_/ / / / / ,<  ___/ /  __/ /__/ /_/ / /  / / /_/ /_/ / 
      /_/    \__,_/_/ /_/_/|_|/____/\___/\___/\__,_/_/  /_/\__/\__, /  
                                             PRESENTS         /____/  
                              Secret-Magpie ✨

      Scan all your github/bitbucket repos from one tool, with multiple tools!

⁠SecretMagpie

⁠Intro

SecretMagpie is a secret detection tool that hunts out all the secrets hiding in your GitHub repositories. It uses multiple tools in one convenient package to scan every branch of every repository in an organisation. It then smooshes all those results together into a lovely json output and reports some big ticket stats right to the screen.

By making use of the opensource tools Trufflehog⁠ 🐷 and Gitleaks⁠, SecretMagpie can highlight a variety of different secrets and ensure that nothing is missed!

⁠Docker

We've kept things nice and simple and bundled everything into a Docker container to enable you to start finding secrets as soon as possible. SecretMagpie has two mandatory parameters, a GitHub organisation name and a GitHub personal access token.

Simply run one of the following commands to get started:

docker run punksecurity/secret-magpie github --org 'github organisation name' --pat 'personal access token'

or

docker run punksecurity/secret-magpie bitbucket --workspace 'workspace name to scan' --username 'your username' --password 'your application password'

⁠Get your results

Copy from the container

docker cp 'container':/app/results/results.[csv/json] /host/path/target

OR Mount the volume

docker -v /localpath:/app/results

⁠Installation

If you prefer not to use Docker then you will need to manually install the following:

You will also need to install the dependencies in requirements.txt by running the following command:

pip install -r requirements.txt

⁠Full Usage

usage:
 secret-magpie {bitbucket,github} [options]

positional arguments:
  {github,bitbucket}

options:
  -h, --help            show this help message and exit
  --out OUT             Output file (default: results)
  --out-format {csv,json}
  --parallel-repos PARALLEL_REPOS
                        Number of repos to process in parallel - more than 3 not advised (default: 4)
  --disable-trufflehog  Scan without trufflehog
  --disable-gitleaks    Scan without gitleaks
  --single-branch       Scan only the default branch
  --dont-store-secret   Do not store the plaintext secret in the results
  --no-stats            Do not output stats summary

github:
  --org ORG             Github organisation name to target
  --pat PAT             Github Personal Access Token for API access and cloning

bitbucket:
  --workspace WORKSPACE
  --username USERNAME
  --password PASSWORD

Tag summary

Content type

Image

Digest

sha256:1a53039f1…

Size

108.8 MB

Last updated

about 2 years ago

docker pull punksecurity/secret-magpie