🌿 secrets-scan v1.0.1 · MIT
Detect hardcoded secrets and credential patterns in a codebase — pre-commit and cron friendly, exit codes you can gate on.
The problem
One careless password = "..." in a commit can outlive every later cleanup — git history remembers. Worse: a half-automated redaction pass that replaces a secret with "***" breaks the code and still leaks a fragment, a case most scanners miss.
What it detects
| Pattern | Severity | Catches |
|---|---|---|
HARDCODED_PASSWORD | CRITICAL | password = "..." assignments |
HARDCODED_API_KEY | CRITICAL | api_key = "..." assignments |
HARDCODED_TOKEN | CRITICAL | bearer / access / auth tokens |
SK_KEY_PATTERN | CRITICAL | sk-… provider API key literals |
PRIVATE_KEY_HEADER | CRITICAL | -----BEGIN … PRIVATE KEY----- blocks |
REDACTED_SECRET | CRITICAL | "***" or "…" where a secret used to be |
CONNECTION_STRING | HIGH | DB URLs with embedded credentials |
ENV_FILE_SECRET | HIGH | secrets committed in .env files |
False-positive guards
- Comment lines skipped (except private keys and
.enventries). - Lines referencing env vars (
os.environ,os.getenv,process.env) skipped. - In Markdown,
REDACTED_SECRETonly fires inside fenced code blocks — prose mentions in docs and changelogs are ignored. ENV_FILE_SECRETapplies to.envfiles only (per-line it would flag everykey = "value"source line)..git,__pycache__,node_modules, venvs excluded automatically.
Install (pip)
pip install secrets-scan @ git+https://mandrilly.com/git/secrets-scan.git
Usage
secrets-scan # scan current directory, fail on CRITICAL secrets-scan /path/to/repo # scan a specific path secrets-scan --json # machine-readable output (cron / CI) secrets-scan --fail-on HIGH # also fail on HIGH severity findings secrets-scan --ignore skips.txt # extra relative paths to skip secrets-scan --version # v1.0.1
Exit codes: 0 clean · 1 findings at/above --fail-on · 2 usage/IO error.
Pre-commit example
#!/bin/sh secrets-scan --json . >/dev/null 2>&1 && exit 0 echo "commit blocked: hardcoded secrets detected (run: secrets-scan)" >&2 exit 1
Self-test
bash run_tests.sh # 7/7 PASS — fixtures cover clean trees, comment/env-var skips, md fences, # .env detection, ignore lists, exit codes