A CLI tool to search GitHub repositories and integrate Gitleaks for scanning.
Project description
GitHubSearchTool
Overview
🔍 GitHubSearchTool is a Python-based command-line tool designed to simplify searching, downloading, and scanning GitHub repositories. The tool seamlessly integrates with Gitleaks to identify and validate secrets such as API keys, tokens, and credentials, enhancing your workflow and security posture.
Features
-
🧑💻 Search GitHub Repositories: Use the GitHub API to search for repositories by keyword.
-
📥 Download Repositories: Select and download repositories directly from the search results.
-
🔒 Secrets Scanning: Automatically scan downloaded repositories with Gitleaks to detect sensitive information.
-
✅ Validation: Validate credentials such as AWS keys, Azure credentials, GitHub tokens, Slack tokens, and more.
-
🎛️ Interactive or Automated: Choose between manual selection or automated operations for downloading and scanning repositories.
-
📜 Custom Gitleaks Rules: Use a custom rules.toml file for advanced secrets detection.
Requirements
-
🐍 Python 3.8 or higher
-
🔍 Gitleaks installed on your system (Installation Guide)
Installation
- Step 1: Clone the Repository
- git clone <repository_url>
- cd GitHubSearchTool
- Step 2: Install Dependencies
- Install the required Python packages:
-pip install -r requirements.txt
- Step 3: Install the Tool
- Use the following command to install the tool:
- python setup.py install
- The installation process will ensure that Gitleaks is installed if it is not already.
Usage
-
Basic Usage
-
githubsearchtool --token <github_token>
-
: The keyword to search for on GitHub.
-
<github_token>: Your GitHub personal access token.
Options
-
📥 --download: Enable manual selection and download of repositories.
-
📂 --download-all: Automatically download all repositories matching the keyword.
-
🔍 --gitleaks: Scan downloaded repositories using Gitleaks.
-
📁 --destination
-
📜 --rule-file
Example Workflows
-
- Search and Display Results
-
githubsearchtool "open source" --token <your_github_token>
-
This will display a list of repositories related to the keyword "open source."
-
- Download All Repositories
- githubsearchtool "open source" --token <your_github_token> --download-all
This will automatically download all matching repositories.
- Scan Repositories with Gitleaks
githubsearchtool "open source" --token <your_github_token> --download-all --gitleaks
This will download and scan all matching repositories for secrets using Gitleaks.
Supported Validations
The tool validates the following credentials:
🔑 AWS Credentials
🔑 Azure Credentials
🔑 Slack Tokens
🔑 Stripe API Keys
🔑 GitHub Personal Access Tokens
🔑 Heroku API Keys
🔑 Dropbox API Keys
🔑 Twilio API Keys
Detected generic passwords are displayed in the terminal without validation.
Using Custom Gitleaks Rules
To enhance the detection capabilities, you can provide a custom rules.toml file for Gitleaks. This file allows you to define additional patterns for secrets detection or adjust existing rules.
Example of Running Gitleaks with Custom Rules
githubsearchtool "security" --token <your_github_token> --download-all --gitleaks --rule-file /path/to/rules.toml
Ensure that your rules.toml file is correctly configured to meet your detection needs.
Dependencies
The following Python packages are required and listed in requirements.txt:
boto3
requests
rich
pyfiglet
stripe
Notes
Ensure Gitleaks is installed and accessible in your system's PATH.
Use a GitHub personal access token with appropriate permissions to access the GitHub API.
Contributing
Contributions are welcome! Please fork the repository and create a pull request with your proposed changes.
License
This project is licensed under the MIT License. See the LICENSE file for details.
Acknowledgments
Special thanks to the creators of Gitleaks and all open-source contributors who make tools like this possible.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file reporecon-1.0.0.tar.gz.
File metadata
- Download URL: reporecon-1.0.0.tar.gz
- Upload date:
- Size: 12.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ddfc4093729c1a62fb894a793daab64c1b81c075e8faeabae066c7ad0bcc9983
|
|
| MD5 |
05f5f2452802b863a4063abca95b40d6
|
|
| BLAKE2b-256 |
ed3b76aeaccc869b28160a4154395427d30f98a7dbdddbc294c2c4d052c71d45
|
File details
Details for the file RepoRecon-1.0.0-py3-none-any.whl.
File metadata
- Download URL: RepoRecon-1.0.0-py3-none-any.whl
- Upload date:
- Size: 11.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2d64ea5ba50f47c5cc699661b4d83f6e8db953327befde99ee92b26608a0f81a
|
|
| MD5 |
6d100ed8f1517251b3761c71f9e7f4b0
|
|
| BLAKE2b-256 |
42a6dc096174e36892ba4168624e0e13d6035384985fe01e8305f822a4a16003
|