A comprehensive tool to detect secrets and sensitive information in Git repositories
Project description
Git Security Scanner
A comprehensive Python tool to detect API keys, passwords, and secrets in Git repositories before they get exposed.
🚀 Features
- 🔍 Detects 25+ Secret Types: AWS keys, API tokens, passwords, private keys, and more
- 🎯 Multiple Scan Modes: Staged files, working directory, commit history
- ⚡ High Performance: Parallel scanning with progress bars and caching
- 📊 Rich Reports: Export to JSON, HTML, CSV, or Markdown
- 🎨 Customizable: Add custom patterns, ignore files, configure severity levels
- 🔧 CI/CD Ready: Pre-commit hooks and pipeline integration
- 🌍 Cross-Platform: Works on Linux, macOS, and Windows
📦 Installation
From PyPI (Recommended)
pip install git-security-scanner
From Source
git clone https://github.com/vyacheslavmeyerzon/security-scanner.git
cd security-scanner
pip install -e .
🔧 Quick Start
Basic Scan
Scan your current repository:
git-security-scanner
Scan Specific Repository
git-security-scanner /path/to/repository
Pre-commit Mode
Check only staged files:
git-security-scanner --pre-commit
Export Results
# JSON format
git-security-scanner --export results.json
# HTML report
git-security-scanner --export report.html
# CSV format
git-security-scanner --export findings.csv
# Markdown report
git-security-scanner --export report.md
🎯 What It Detects
Cloud Services
- AWS Access Keys and Secret Keys
- Azure Storage Keys
- Google Cloud API Keys and OAuth Tokens
AI/ML Platforms
- OpenAI API Keys
- Anthropic (Claude) API Keys
- HuggingFace Tokens
- Cohere API Keys
Version Control
- GitHub Personal Access Tokens
- GitLab Access Tokens
- Bitbucket App Passwords
Databases
- MongoDB Connection Strings
- PostgreSQL Connection URLs
- MySQL Connection Strings
Communication & More
- Slack Tokens
- Discord Bot Tokens
- Stripe API Keys
- JWT Tokens
- Private Keys (RSA, EC, DSA)
- Generic Passwords and Secrets
📋 Command Line Options
usage: git-security-scanner [-h] [-v] [-c CONFIG] [--pre-commit] [--no-history]
[--history-limit N] [--export FILE] [--quiet]
[--min-severity {LOW,MEDIUM,HIGH,CRITICAL}]
[--show-patterns] [--no-color] [--no-progress]
[path]
Detect API keys, passwords, and secrets in Git repositories
positional arguments:
path Path to Git repository (default: current directory)
optional arguments:
-h, --help Show help message
-v, --version Show version
-c, --config Path to config file
--pre-commit Scan only staged files
--no-history Skip commit history scan
--history-limit N Limit history scan to N commits (default: 100)
--export FILE Export findings (.json, .html, .csv, .md)
--quiet Minimal output
--min-severity LEVEL Minimum severity to report
--show-patterns Show all detection patterns
--no-color Disable colored output
--no-progress Disable progress bars
⚙️ Configuration
Configuration File
Create .gitscannerrc.json or .gitscannerrc.yaml:
{
"patterns": {
"custom": [
{
"name": "Company API Key",
"pattern": "COMP-[A-Z0-9]{32}",
"severity": "HIGH",
"description": "Internal company API key"
}
],
"disabled": ["Generic Secret", "Environment Variable"]
},
"scan": {
"history_limit": 50,
"max_file_size_mb": 5,
"parallel_workers": 4
},
"output": {
"format": "console",
"min_severity": "MEDIUM",
"color": true
},
"cache": {
"enabled": true,
"ttl_hours": 48
}
}
Environment Variables
export SCANNER_HISTORY_LIMIT=25
export SCANNER_MIN_SEVERITY=HIGH
export SCANNER_QUIET=true
export SCANNER_NO_COLOR=true
Ignore Files
Create .gitscannerignore:
# Ignore test files
tests/
*.test.py
# Ignore vendor directories
vendor/
node_modules/
# Ignore specific files
config.example.json
🪝 Git Hook Setup
Pre-commit Hook
# Install as pre-commit hook
cat > .git/hooks/pre-commit << 'EOF'
#!/bin/bash
git-security-scanner --pre-commit
EOF
chmod +x .git/hooks/pre-commit
Using pre-commit Framework
Add to .pre-commit-config.yaml:
repos:
- repo: local
hooks:
- id: security-scanner
name: Git Security Scanner
entry: git-security-scanner --pre-commit
language: system
pass_filenames: false
🔄 CI/CD Integration
GitHub Actions
name: Security Scan
on: [push, pull_request]
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
with:
fetch-depth: 0 # Full history for commit scanning
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: '3.11'
- name: Install scanner
run: pip install git-security-scanner
- name: Run security scan
run: git-security-scanner --export results.json
- name: Upload results
uses: actions/upload-artifact@v3
if: failure()
with:
name: security-scan-results
path: results.json
GitLab CI
security_scan:
stage: test
script:
- pip install git-security-scanner
- git-security-scanner --quiet --export report.html
artifacts:
reports:
expose_as: 'Security Report'
paths: ['report.html']
when: on_failure
📈 Understanding Results
Severity Levels
- 🔴 CRITICAL: Immediate action required (database credentials, private keys)
- 🟡 HIGH: Serious issues (API keys, access tokens)
- 🟣 MEDIUM: Should be reviewed (generic secrets, weak patterns)
- 🔵 LOW: Minor concerns (environment variables, configuration)
Example Output
=== Scanning working directory ===
Scanning 150 files in working directory...
100%|████████████| 150/150 [00:02<00:00, 68.42files/s]
[CRITICAL] MongoDB Connection
Description: MongoDB Connection String with credentials
File: config/database.py
Line: 15
Secret: mongodb://user:****@localhost:27017/db
[HIGH] GitHub Token
Description: GitHub Personal Access Token
File: .env.example
Line: 3
Secret: ghp_****************************1234
Summary: Found 2 potential secrets:
CRITICAL: 1
HIGH: 1
🛡️ Best Practices
If Secrets Are Found
- Immediately rotate the exposed credentials
- Remove from history using
git filter-branchor BFG Repo-Cleaner - Audit access logs to check if credentials were compromised
- Enable 2FA where possible
Prevention
- Use environment variables for sensitive data
- Implement secret management tools (HashiCorp Vault, AWS Secrets Manager)
- Add
.envfiles to.gitignore - Use
.gitscannerignorefor false positives - Run scanner in CI/CD pipelines
- Set up pre-commit hooks
🤝 Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
- Fork the repository
- Create your feature branch (
git checkout -b feature/AmazingFeature) - Commit your changes (
git commit -m 'Add some AmazingFeature') - Push to the branch (
git push origin feature/AmazingFeature) - Open a Pull Request
📝 License
This project is licensed under the MIT License - see the LICENSE file for details.
🙏 Acknowledgments
- Thanks to all contributors who have helped improve this tool
- Inspired by similar tools like truffleHog and GitLeaks
- Built with love for the security community
Remember: Never commit secrets to Git. If you do, rotate them immediately! 🔐
📚 Documentation
For detailed documentation, visit our Wiki.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file git_security_scanner-0.1.2.tar.gz.
File metadata
- Download URL: git_security_scanner-0.1.2.tar.gz
- Upload date:
- Size: 58.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4fe72457743031f22a90500ee01027a27757c68c73f0d81f0b796f6cd3560eeb
|
|
| MD5 |
c3787b3cfce08fa8e5bad7acbec7b080
|
|
| BLAKE2b-256 |
71d74e5729a5ac47f63ad8963b4d8bf06932cde6d0d9e867f37d63e80add8a5e
|
File details
Details for the file git_security_scanner-0.1.2-py3-none-any.whl.
File metadata
- Download URL: git_security_scanner-0.1.2-py3-none-any.whl
- Upload date:
- Size: 32.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
59c10170838cc780700444b5636229b882fac2df940e801336055fcc438f4a3a
|
|
| MD5 |
16c5d1b826f06e7d07aa26f9cc85c62a
|
|
| BLAKE2b-256 |
8a3e65a364ff13114cd43a0b4a80fa60b524bae3d65bdfaab721cd7ed59a4d90
|