Skip to main content

ggshield: protect your code with GitGuardian

PyPI Docker Image Version (latest semver) License GitHub stars GitHub Workflow Status Codecov

ggshield is a CLI application that runs in your local environment or in a CI environment to help you detect more than 500+ types of secrets.

ggshield uses our public API through py-gitguardian to scan and detect potential vulnerabilities in files and other text content.

Only metadata such as call time, request size and scan mode is stored from scans using ggshield, therefore secrets will not be displayed on your dashboard and your files and secrets won't be stored.

Table of Contents

Installation

The quickest way to install ggshield.

Linux / macOS:

curl -sSfL \
  https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.sh | bash

Windows (PowerShell):

irm https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.ps1 | iex

Or, if you prefer curl (bundled with Windows 10+):

curl.exe -sSL https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.ps1 | powershell -NoProfile -ExecutionPolicy Bypass -Command -

The script accepts options such as --instance and --plugin (install a plugin). For the EU workspace or a self-hosted instance, set the GITGUARDIAN_INSTANCE environment variable (or pass --instance <URL>) before running.

See scripts/install/README.md for the full list of options, the other install methods, and how to uninstall.

The methods below install the CLI manually instead.

macOS

Homebrew

You can install ggshield using Homebrew:

brew install ggshield

Upgrading is handled by Homebrew.

Standalone .pkg package

Alternatively, you can download and install a standalone .pkg package from ggshield release page.

This package does not require installing Python, but you have to manually download new versions.

Linux

Deb and RPM packages

Deb and RPM packages are available on Cloudsmith.

Setup instructions:

Upgrading is handled by the package manager.

Windows

Chocolatey

ggshield is available via the Chocolatey package manager:

choco install ggshield

MSI installer

Download the MSI installer from the ggshield release page and install it:

msiexec /i ggshield-VERSION-x86_64-pc-windows-msvc.msi

Standalone .zip archive

We provide a standalone .zip archive on ggshield release page.

Unpack the archive on your disk, then add the directory containing the ggshield.exe file to %PATH%.

This archive does not require installing Python, but you have to manually download new versions.

All operating systems

ggshield can be installed on all supported operating systems via its PyPI package.

It requires a supported version of Python (not EOL) (except for standalone packages) and git.

If you don't use our packaged versions of ggshield, please be aware that we follow the Python release cycle and do not support versions that have reached EOL.

Using pipx

The recommended way to install ggshield from PyPI is to use pipx, which will install it in an isolated environment:

pipx install ggshield

To upgrade your installation, run:

pipx upgrade ggshield

Using pip

You can also install ggshield from PyPI using pip, but this is not recommended because the installation is not isolated, so other applications or packages installed this way may affect your ggshield installation. This method will also not work if your Python installation is declared as externally managed (for example when using the system Python on operating systems like Debian 12):

pip install --user ggshield

To upgrade your installation, run:

pip install --user --upgrade ggshield

Initial setup

Using ggshield auth login

To use ggshield you need to authenticate against GitGuardian servers. To do so, use the ggshield auth login command. This command automates the provisioning of a personal access token and its configuration on the local workstation.

You can learn more about it from ggshield auth login documentation.

Manual setup

You can also create your personal access token manually and store it in the GITGUARDIAN_API_KEY environment variable to complete the setup.

Getting started

Secrets

You can now use ggshield to search for secrets:

  • in files: ggshield secret scan path -r .
  • in repositories: ggshield secret scan repo .
  • in Docker images (docker command must be available): ggshield secret scan docker ubuntu:22.04
  • in Pypi packages (pip command must be available): ggshield secret scan pypi flask
  • and more, have a look at ggshield secret scan --help output for details.

Migrating a legacy configuration file

If ggshield reports that your .gitguardian.yaml (or .gitguardian.yml) config file uses a deprecated format, migrate it to the latest version with:

ggshield config migrate

By default, this looks for the configuration file in the current directory, so run it from the directory containing the file. To run it from anywhere, point ggshield to the file explicitly:

ggshield --config-path path/to/.gitguardian.yaml config migrate

The previous version of the file is kept as a .old backup next to it.

Integrations

You can integrate ggshield in your CI/CD workflow.

To catch errors earlier, use ggshield as a pre-commit, pre-push or pre-receive Git hook.

AI coding assistants

ggshield can scan interactions between you and your AI coding assistant in real time, blocking actions that contain secrets before they are executed.

You can install the hooks with the ggshield install command.

Supported tools: Cursor, Claude Code, Copilot Chat, Codex, and Mistral Vibe 2.21+.

Learn more

For more information, have a look at the documentation

Output

If no secrets have been found, the exit code will be 0:

ggshield secret scan pre-commit

If a secret is found in your staged code or in your CI, you will have an alert giving you the filename where the secret has been found and a patch giving you the position of the secret in the file:

ggshield secret scan pre-commit
2 incidents have been found in file production.rb

11 | config.paperclip_defaults = {
12 |     :s3_credentials => {
13 |     :bucket => "XXX",
14 |     :access_key_id => "XXXXXXXXXXXXXXXXXXXX",
                            |_____AWS Keys_____|

15 |     :secret_access_key => "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
                                |_______________AWS Keys_______________|

16 |     }
17 | }

Lines that are too long are truncated to match the size of the terminal, unless the verbose mode is used (-v or --verbose).

Related open source projects

License

ggshield is MIT licensed.

Release files for ggshield 1.55.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ggshield 1.55.0
File Size Uploaded
ggshield-1.55.0.tar.gz 1.0 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for ggshield 1.55.0
File
ggshield-1.55.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
ggshield-1.55.0-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
ggshield-1.55.0-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
ggshield-1.55.0-py3-none-manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
ggshield-1.55.0-py3-none-manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
ggshield-1.55.0-py3-none-macosx_11_0_universal2.whl Python 3 none macOS 11.0+ universal2 (ARM64, x86-64) Details
ggshield-1.55.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.4 MB

Release files / ggshield-1.55.0.tar.gz

Download URL ggshield-1.55.0.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
06b8bbef8885abaa18ab87c70708584e625a1ddbd0902ccf93ba97e15784f766
BLAKE2b-256 checksum
How to use checksums
1c93bebb2317a2e1eda08870f39a8caf6ee769e0a50cfc899976ec163350ecd1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-win_amd64.whl

Download URL ggshield-1.55.0-py3-none-win_amd64.whl
Size 2.4 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
020a29f918f88d6c0e0b6ab2c18bc22feab5091b3ed0004c2aece77c768c4304
BLAKE2b-256 checksum
How to use checksums
fa9ecf0c0ffc3070be5efd48b94e2f9c6a69b74702bab13840afbb5467334486
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-musllinux_1_2_x86_64.whl

Download URL ggshield-1.55.0-py3-none-musllinux_1_2_x86_64.whl
Size 3.2 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
45d2c41a20bfbb79d5197923bf039a3a62ce0a0bb3150d01da59fae558dcf3c0
BLAKE2b-256 checksum
How to use checksums
49bb06c12059e706e55fd6863f311fd4d12b816eb24315e667627054eaa7e888
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-musllinux_1_2_aarch64.whl

Download URL ggshield-1.55.0-py3-none-musllinux_1_2_aarch64.whl
Size 3.0 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
5ccd71dfffc12e774bb4a5247f7a8ef43d69fd915dece493873d8aabb2ca6f16
BLAKE2b-256 checksum
How to use checksums
ed576ac0c230f61aa26cf732aab1f886e0029c378e09dbf78c806decf65810cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-manylinux2014_x86_64.whl

Download URL ggshield-1.55.0-py3-none-manylinux2014_x86_64.whl
Size 3.2 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
b7e3042cae0b7c452625cae5c030a146d6c711a249e51f3caa6a46585bcf9e27
BLAKE2b-256 checksum
How to use checksums
251c5f5f8fd32c562d4e6f8af831caeb2d8cb317990130916b3d58e5b397821d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-manylinux2014_aarch64.whl

Download URL ggshield-1.55.0-py3-none-manylinux2014_aarch64.whl
Size 3.0 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
e8dba0940bfa0fbf4278df3825c6b5c61ad7f34dd0e0ef5d22529a538e366238
BLAKE2b-256 checksum
How to use checksums
fce9d693a0bc509fce9540e2c6b9ccfc00cf886468adc9d26476f96751066074
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-macosx_11_0_universal2.whl

Download URL ggshield-1.55.0-py3-none-macosx_11_0_universal2.whl
Size 4.2 MB
Tags Python 3 macOS 11.0+ universal2 (ARM64, x86-64)
SHA-256 checksum
How to use checksums
f9325e5367896e0c218037e1eab4cacf07f0abd3aa68f760649d2d52083d9e88
BLAKE2b-256 checksum
How to use checksums
8604dbaeb0ed4a74ff3c624c0ce2aff396ec3674f7f165b619d0140bb03d5657
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0-py3-none-any.whl

Download URL ggshield-1.55.0-py3-none-any.whl
Size 383.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9c7484ff7e7a0b029fd716ff06edd9c94f519fdad9ce5d299ca264f8224cab18
BLAKE2b-256 checksum
How to use checksums
3fcc7d16dbb5c5885f08092d43a8ded955d2610ba6bc23d008a34e4fa056cb15
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.55.0 This release

8 release files

1.54.0

8 release files

1.53.0

2 release files

1.52.2

2 release files

1.52.1

2 release files

1.52.0

2 release files

1.51.0

2 release files

1.50.3

2 release files

1.50.2

2 release files

1.50.1

2 release files

1.50.0

2 release files

1.49.0

2 release files

1.48.0

2 release files

1.47.0

2 release files

1.46.0

2 release files

1.45.0

2 release files

1.44.1

2 release files

1.43.0

2 release files

1.42.0

2 release files

1.41.0

2 release files

1.40.0

2 release files

1.39.0

2 release files

1.38.0

2 release files

1.36.0

2 release files

1.34.0

2 release files

1.33.0

2 release files

1.32.2

2 release files

1.32.0

2 release files

1.31.0

2 release files

1.30.1

2 release files

1.29.0

2 release files

1.28.0

2 release files

1.27.0

2 release files

1.26.0

2 release files

1.25.0

2 release files

1.24.0

2 release files

1.22.0

2 release files

1.20.0

2 release files

1.19.1

2 release files

1.18.1

2 release files

1.18.0

2 release files

1.17.3

2 release files

1.17.2

2 release files

1.17.1

2 release files

1.17.0

2 release files

1.16.0

2 release files

1.15.1

2 release files

1.15.0

2 release files

1.14.5

2 release files

1.14.4

2 release files

1.14.2

2 release files

1.14.1

2 release files

1.13.6

2 release files

1.13.5

2 release files

1.13.4

2 release files

1.13.3

2 release files

1.13.2

2 release files

1.13.1

2 release files

1.13.0

2 release files

1.12.0

2 release files

1.11.0

2 release files

1.10.8

2 release files

1.10.7

2 release files

1.10.6

2 release files

1.10.5

2 release files

1.10.1

2 release files

1.10.0

2 release files

1.9.0

2 release files

1.8.2

2 release files

1.8.1

2 release files

1.8.0

2 release files

1.7.3

2 release files

1.7.2

2 release files

1.7.1

2 release files

1.7.0

2 release files

1.6.1

2 release files

1.6.0

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page