Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

ggshield: protect your code with GitGuardian

PyPI Docker Image Version (latest semver) License GitHub stars GitHub Workflow Status Codecov

ggshield is a CLI application that runs in your local environment or in a CI environment to help you detect more than 500+ types of secrets.

ggshield uses our public API through py-gitguardian to scan and detect potential vulnerabilities in files and other text content.

Only metadata such as call time, request size and scan mode is stored from scans using ggshield, therefore secrets will not be displayed on your dashboard and your files and secrets won't be stored.

Table of Contents

Installation

The quickest way to install ggshield.

Linux / macOS:

curl -sSfL \
  https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.sh | bash

Windows (PowerShell):

irm https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.ps1 | iex

Or, if you prefer curl (bundled with Windows 10+):

curl.exe -sSL https://raw.githubusercontent.com/GitGuardian/ggshield/main/scripts/install/install.ps1 | powershell -NoProfile -ExecutionPolicy Bypass -Command -

The script accepts options such as --instance and --plugin (install a plugin). For the EU workspace or a self-hosted instance, set the GITGUARDIAN_INSTANCE environment variable (or pass --instance <URL>) before running.

See scripts/install/README.md for the full list of options, the other install methods, and how to uninstall.

The methods below install the CLI manually instead.

macOS

Homebrew

You can install ggshield using Homebrew:

brew install ggshield

Upgrading is handled by Homebrew.

Standalone .pkg package

Alternatively, you can download and install a standalone .pkg package from ggshield release page.

This package does not require installing Python, but you have to manually download new versions.

Linux

Deb and RPM packages

Deb and RPM packages are available on Cloudsmith.

Setup instructions:

Upgrading is handled by the package manager.

Windows

Chocolatey

ggshield is available via the Chocolatey package manager:

choco install ggshield

MSI installer

Download the MSI installer from the ggshield release page and install it:

msiexec /i ggshield-VERSION-x86_64-pc-windows-msvc.msi

Standalone .zip archive

We provide a standalone .zip archive on ggshield release page.

Unpack the archive on your disk, then add the directory containing the ggshield.exe file to %PATH%.

This archive does not require installing Python, but you have to manually download new versions.

All operating systems

ggshield can be installed on all supported operating systems via its PyPI package.

It requires a supported version of Python (not EOL) (except for standalone packages) and git.

If you don't use our packaged versions of ggshield, please be aware that we follow the Python release cycle and do not support versions that have reached EOL.

Using pipx

The recommended way to install ggshield from PyPI is to use pipx, which will install it in an isolated environment:

pipx install ggshield

To upgrade your installation, run:

pipx upgrade ggshield

Using pip

You can also install ggshield from PyPI using pip, but this is not recommended because the installation is not isolated, so other applications or packages installed this way may affect your ggshield installation. This method will also not work if your Python installation is declared as externally managed (for example when using the system Python on operating systems like Debian 12):

pip install --user ggshield

To upgrade your installation, run:

pip install --user --upgrade ggshield

Initial setup

Using ggshield auth login

To use ggshield you need to authenticate against GitGuardian servers. To do so, use the ggshield auth login command. This command automates the provisioning of a personal access token and its configuration on the local workstation.

You can learn more about it from ggshield auth login documentation.

Manual setup

You can also create your personal access token manually and store it in the GITGUARDIAN_API_KEY environment variable to complete the setup.

Getting started

Secrets

You can now use ggshield to search for secrets:

  • in files: ggshield secret scan path -r .
  • in repositories: ggshield secret scan repo .
  • in Docker images (docker command must be available): ggshield secret scan docker ubuntu:22.04
  • in Pypi packages (pip command must be available): ggshield secret scan pypi flask
  • and more, have a look at ggshield secret scan --help output for details.

Migrating a legacy configuration file

If ggshield reports that your .gitguardian.yaml (or .gitguardian.yml) config file uses a deprecated format, migrate it to the latest version with:

ggshield config migrate

By default, this looks for the configuration file in the current directory, so run it from the directory containing the file. To run it from anywhere, point ggshield to the file explicitly:

ggshield --config-path path/to/.gitguardian.yaml config migrate

The previous version of the file is kept as a .old backup next to it.

Integrations

You can integrate ggshield in your CI/CD workflow.

To catch errors earlier, use ggshield as a pre-commit, pre-push or pre-receive Git hook.

AI coding assistants

ggshield can scan interactions between you and your AI coding assistant in real time, blocking actions that contain secrets before they are executed.

You can install the hooks with the ggshield install command.

Supported tools: Cursor, Claude Code, Copilot Chat, Codex, and Mistral Vibe 2.21+.

Learn more

For more information, have a look at the documentation

Output

If no secrets have been found, the exit code will be 0:

ggshield secret scan pre-commit

If a secret is found in your staged code or in your CI, you will have an alert giving you the filename where the secret has been found and a patch giving you the position of the secret in the file:

ggshield secret scan pre-commit
2 incidents have been found in file production.rb

11 | config.paperclip_defaults = {
12 |     :s3_credentials => {
13 |     :bucket => "XXX",
14 |     :access_key_id => "XXXXXXXXXXXXXXXXXXXX",
                            |_____AWS Keys_____|

15 |     :secret_access_key => "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"
                                |_______________AWS Keys_______________|

16 |     }
17 | }

Lines that are too long are truncated to match the size of the terminal, unless the verbose mode is used (-v or --verbose).

Related open source projects

License

ggshield is MIT licensed.

Release files for ggshield 1.55.0rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ggshield 1.55.0rc1
File Size Uploaded
ggshield-1.55.0rc1.tar.gz 1.0 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for ggshield 1.55.0rc1
File
ggshield-1.55.0rc1-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
ggshield-1.55.0rc1-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
ggshield-1.55.0rc1-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
ggshield-1.55.0rc1-py3-none-manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
ggshield-1.55.0rc1-py3-none-manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
ggshield-1.55.0rc1-py3-none-macosx_11_0_universal2.whl Python 3 none macOS 11.0+ universal2 (ARM64, x86-64) Details
ggshield-1.55.0rc1-py3-none-any.whl Python 3 none any Details

Total release size: 20.4 MB

Release files / ggshield-1.55.0rc1.tar.gz

Download URL ggshield-1.55.0rc1.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
202c3b7c9820ce7d332354ebd30ebed433e976a53e88a627ac158ddfa9bd7b2d
BLAKE2b-256 checksum
How to use checksums
cc34a2ad65ae08681fd92484989a2eda5ea6d1b41348d8a5d953067c54533b12
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-win_amd64.whl

Download URL ggshield-1.55.0rc1-py3-none-win_amd64.whl
Size 2.4 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
57704b4f72a62fffea06265ef9973861aecfb79f8b28b3233e64b916628f3819
BLAKE2b-256 checksum
How to use checksums
5709edee0e3ae62767ee8ca2ac2a0181961f864a174b5e5dce4f65ee24a44bb5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-musllinux_1_2_x86_64.whl

Download URL ggshield-1.55.0rc1-py3-none-musllinux_1_2_x86_64.whl
Size 3.2 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
8bcc44f0005a240a7c384bb7b788a41db468ce4e5b002fadcb477d42c0ac5a09
BLAKE2b-256 checksum
How to use checksums
f622305967f3928d2ecfc5f66f45d44f822f0dc4ee830234ad48ff93d6595027
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-musllinux_1_2_aarch64.whl

Download URL ggshield-1.55.0rc1-py3-none-musllinux_1_2_aarch64.whl
Size 3.0 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
a0da196e633e7fc4fe8a845a94876ce2014dd53bc357ee2495122dbe6f5bc0c7
BLAKE2b-256 checksum
How to use checksums
f8cce5c1dfaeb1d4a644b87ae503c5f42f162d422b8a1bf8e93de58ebfa22dfe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-manylinux2014_x86_64.whl

Download URL ggshield-1.55.0rc1-py3-none-manylinux2014_x86_64.whl
Size 3.2 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
f1abc1d14e4723519bf4e5d2850461317435f74fe9a989840076d00d7bbfdc30
BLAKE2b-256 checksum
How to use checksums
f85ea68c75876c7dc62c50df368ddae5bd1313c2a84ae67b926afde4f920bf32
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-manylinux2014_aarch64.whl

Download URL ggshield-1.55.0rc1-py3-none-manylinux2014_aarch64.whl
Size 3.0 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
5c2e520856b75255b19d19c81e8278390f8f033dabe96da1d173eb6cd77b0bdc
BLAKE2b-256 checksum
How to use checksums
2b2ab38cf6b8bc28fa7f3086f30e1caec836203e5c16c53c47db21a3cc62ad55
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-macosx_11_0_universal2.whl

Download URL ggshield-1.55.0rc1-py3-none-macosx_11_0_universal2.whl
Size 4.2 MB
Tags Python 3 macOS 11.0+ universal2 (ARM64, x86-64)
SHA-256 checksum
How to use checksums
df09ef0fc99a6287753d7de4f11e2a33890cee25e4a8bd57d171a604fa14c9d5
BLAKE2b-256 checksum
How to use checksums
662370953bdb0506425348cb41c2537db6ec5e27a397b86b7674b9aca827e001
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release files / ggshield-1.55.0rc1-py3-none-any.whl

Download URL ggshield-1.55.0rc1-py3-none-any.whl
Size 383.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
75e5b828987d9e483994ae24a4ab0727ee8b00d81948efc790252ee4588eaeab
BLAKE2b-256 checksum
How to use checksums
da5893b956880a5de86241dcca7d44c26b55b00da0cd26cd4f33b886dc9e0f63
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.

Transparency log

Release history Release notifications | RSS feed

1.55.0

8 release files

This release

1.55.0rc1 This release

8 release files

1.54.0

8 release files

1.53.0

2 release files

1.52.2

2 release files

1.52.1

2 release files

1.52.0

2 release files

1.51.0

2 release files

1.50.3

2 release files

1.50.2

2 release files

1.50.1

2 release files

1.50.0

2 release files

1.49.0

2 release files

1.48.0

2 release files

1.47.0

2 release files

1.46.0

2 release files

1.45.0

2 release files

1.44.1

2 release files

1.43.0

2 release files

1.42.0

2 release files

1.41.0

2 release files

1.40.0

2 release files

1.39.0

2 release files

1.38.0

2 release files

1.36.0

2 release files

1.34.0

2 release files

1.33.0

2 release files

1.32.2

2 release files

1.32.0

2 release files

1.31.0

2 release files

1.30.1

2 release files

1.29.0

2 release files

1.28.0

2 release files

1.27.0

2 release files

1.26.0

2 release files

1.25.0

2 release files

1.24.0

2 release files

1.22.0

2 release files

1.20.0

2 release files

1.19.1

2 release files

1.18.1

2 release files

1.18.0

2 release files

1.17.3

2 release files

1.17.2

2 release files

1.17.1

2 release files

1.17.0

2 release files

1.16.0

2 release files

1.15.1

2 release files

1.15.0

2 release files

1.14.5

2 release files

1.14.4

2 release files

1.14.2

2 release files

1.14.1

2 release files

1.13.6

2 release files

1.13.5

2 release files

1.13.4

2 release files

1.13.3

2 release files

1.13.2

2 release files

1.13.1

2 release files

1.13.0

2 release files

1.12.0

2 release files

1.11.0

2 release files

1.10.8

2 release files

1.10.7

2 release files

1.10.6

2 release files

1.10.5

2 release files

1.10.1

2 release files

1.10.0

2 release files

1.9.0

2 release files

1.8.2

2 release files

1.8.1

2 release files

1.8.0

2 release files

1.7.3

2 release files

1.7.2

2 release files

1.7.1

2 release files

1.7.0

2 release files

1.6.1

2 release files

1.6.0

2 release files

1.5.0

2 release files

1.4.0

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page