Git Secret Scanner

Detects leaked secrets in Git repositories by scanning full commit history with Gitleaks rules and the GitHub Secret Scanning API, identifying exposed API keys, tokens, and credentials.

agentskillexchange Updated 28 repo stars

File contents

Git Secret Scanner

Detects leaked secrets in Git repositories using pattern-based scanning with Gitleaks rule definitions and the GitHub Secret Scanning API. Identifies exposed API keys, tokens, and credentials across full commit history using git log --all -p analysis.

Installation

Use the upstream install or setup path that matches your environment:

  • brew install gitleaks
  • docker pull zricethezav/gitleaks:latest
  • docker run -v ${path_to_host_folder_to_scan}:/path zricethezav/gitleaks:latest [COMMAND] [OPTIONS] [SOURCE_PATH]
  • docker pull ghcr.io/gitleaks/gitleaks:latest

Requirements and caveats from upstream:

Basic usage or getting-started notes:

Source

agentskillexchange/skills/tree/main/skills/git-secret-scanner commit f5d846a8f5

Frequently asked questions

npx skillmds@latest add agentskillexchange/git-secret-scanner