Sensitive data detection tool with pre-commit hook support
Project description
Ferret Scan Python Package
A Python wrapper for Ferret Scan, a sensitive data detection tool. This package provides easy installation and seamless pre-commit hook integration.
Installation
pip install ferret-scan
Usage
Command Line
After installation, use ferret-scan exactly like the native binary:
# Basic scan
ferret-scan --file document.txt
# JSON output
ferret-scan --file document.txt --format json
# Quiet mode for scripts
ferret-scan --file document.txt --quiet
# Pre-commit mode with optimizations
ferret-scan --pre-commit-mode --confidence high,medium --checks all
Pre-commit Hook
Ferret Scan provides multiple pre-commit hook configurations for different security requirements. Add to your .pre-commit-config.yaml:
Default Configuration (Recommended)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan
Strict Security (Blocks on high confidence findings)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-strict
Advisory Mode (Shows findings but never blocks)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-advisory
Secrets Only (Focus on API keys and tokens)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-secrets
Financial Data (Credit cards and financial info)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-financial
PII Detection (SSN, passport, email)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-pii
Metadata Check (Document metadata scanning)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-metadata
CI/CD Optimized (Structured output for pipelines)
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan-ci
Custom Configuration
You can also customize any hook with additional arguments:
repos:
- repo: https://github.com/awslabs/ferret-scan
rev: v1.0.0
hooks:
- id: ferret-scan
args: ['--confidence', 'high', '--checks', 'CREDIT_CARD,SECRETS', '--verbose']
Local Installation
For local installations, use the ferret-scan command directly:
repos:
- repo: local
hooks:
- id: ferret-scan
name: Ferret Scan - Sensitive Data Detection
entry: ferret-scan
language: system
files: '\.(txt|py|js|ts|go|java|json|yaml|yml|md|csv|log|conf|config|ini|env)$'
args: ['--pre-commit-mode', '--confidence', 'high,medium']
How It Works
This Python package:
- Automatic Binary Download: Downloads the appropriate ferret-scan binary for your platform (Linux/macOS/Windows, x86_64/ARM64)
- Transparent Execution: Passes all arguments directly to the native binary
- Cross-Platform: Works on all platforms supported by ferret-scan
- Pre-commit Ready: Integrates seamlessly with pre-commit hooks with automatic optimizations
Supported Platforms
- Linux: x86_64, ARM64
- macOS: x86_64 (Intel), ARM64 (Apple Silicon)
- Windows: x86_64, ARM64
Features
All features of the native ferret-scan binary are available:
- Sensitive Data Detection: Credit cards, passports, SSNs, API keys, etc.
- Multiple Formats: Text, JSON, CSV, YAML, JUnit, GitLab SAST output
- Document Processing: PDF, Office documents, images
- Pre-commit Optimizations: Automatic quiet mode, no colors, appropriate exit codes
- Suppression Rules: Manage false positives
- Configuration: YAML config files and profiles
- Redaction: Remove sensitive data from documents
Command Line Options
The Python package supports all command-line options of the native binary:
--file: Input file, directory, or glob pattern--format: Output format (text, json, csv, yaml, junit, gitlab-sast)--confidence: Confidence levels (high, medium, low, combinations)--checks: Specific checks to run (CREDIT_CARD, SECRETS, SSN, etc.)--pre-commit-mode: Enable pre-commit optimizations--verbose: Detailed information for findings--quiet: Suppress progress output--no-color: Disable colored output--recursive: Recursively scan directories--enable-preprocessors: Enable document text extraction--config: Configuration file path--profile: Configuration profile name
Requirements
- Python 3.7+
- Internet connection (for initial binary download)
License
Apache License 2.0 - see the LICENSE file for details.
Contributing
See the main Ferret Scan repository for contribution guidelines.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ferret_scan-1.3.20.tar.gz.
File metadata
- Download URL: ferret_scan-1.3.20.tar.gz
- Upload date:
- Size: 52.1 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b7c0241cd044d1f0818dc32d3cace3089d41640b6b1e95d149f0a3d0752693e9
|
|
| MD5 |
3dfd10ecdb67b13e657b507dc87c7114
|
|
| BLAKE2b-256 |
8ae686b6ff2eb75322e0caed6f7240d4b85d0429b3fb5da86febf3653ec62132
|
Provenance
The following attestation bundles were made for ferret_scan-1.3.20.tar.gz:
Publisher:
python-package.yml on awslabs/ferret-scan
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ferret_scan-1.3.20.tar.gz -
Subject digest:
b7c0241cd044d1f0818dc32d3cace3089d41640b6b1e95d149f0a3d0752693e9 - Sigstore transparency entry: 668273263
- Sigstore integration time:
-
Permalink:
awslabs/ferret-scan@b4f9d3474a23732ce5e4753a94af7271b8b04236 -
Branch / Tag:
refs/tags/v1.3.20 - Owner: https://github.com/awslabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-package.yml@b4f9d3474a23732ce5e4753a94af7271b8b04236 -
Trigger Event:
push
-
Statement type:
File details
Details for the file ferret_scan-1.3.20-py3-none-any.whl.
File metadata
- Download URL: ferret_scan-1.3.20-py3-none-any.whl
- Upload date:
- Size: 52.3 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f47fa98dff6cabf3313674d052b289d96c4a5db4dee28f8e0e33702e91577e75
|
|
| MD5 |
04abbb2b1b077743724331ef28e92639
|
|
| BLAKE2b-256 |
a4db91fbd9e136ecea4832e449ac866601314595c9227a73ec747786e5961fdc
|
Provenance
The following attestation bundles were made for ferret_scan-1.3.20-py3-none-any.whl:
Publisher:
python-package.yml on awslabs/ferret-scan
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
ferret_scan-1.3.20-py3-none-any.whl -
Subject digest:
f47fa98dff6cabf3313674d052b289d96c4a5db4dee28f8e0e33702e91577e75 - Sigstore transparency entry: 668273277
- Sigstore integration time:
-
Permalink:
awslabs/ferret-scan@b4f9d3474a23732ce5e4753a94af7271b8b04236 -
Branch / Tag:
refs/tags/v1.3.20 - Owner: https://github.com/awslabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
python-package.yml@b4f9d3474a23732ce5e4753a94af7271b8b04236 -
Trigger Event:
push
-
Statement type: