Skip to main content

SafeCommit

A lightweight, cross-platform Python CLI that scans projects for exposed API keys, credentials, tokens, connection strings, private keys, and other sensitive information before you commit.

Prevent accidentally leaking secrets to Git repositories with fast, recursive, regex-based scanning.


Features

  • 🔍 Detects 25+ common secret types
  • 📂 Recursive project scanning
  • ⚡ Fast regex-based detection
  • 🖥️ Cross-platform (Windows, Linux, macOS)
  • 🎨 Beautiful terminal output powered by Rich
  • 📄 Reports file path, line number, severity, matched pattern, and matched value
  • 📦 Lightweight with zero external services
  • 🚀 Simple installation using pip

Installation

Install from PyPI:

pip install safecommit-cli

Verify installation:

safecommit --version

Quick Start

Scan the current project:

safecommit scan .

Scan another directory:

safecommit scan /path/to/project

Example:

safecommit scan D:\Projects\MyApp

Example Output

Scanning: D:\Projects\MyApp

Found 2 potential issue(s).

╭──────────── Secret Detected ────────────╮
│ File      : backend/config.py           │
│ Line      : 18                          │
│ Severity  : HIGH                        │
│ Pattern   : OpenAI API Key              │
│ Match     : sk-proj-****************    │
╰─────────────────────────────────────────╯

Supported Secret Types

API Keys & Tokens

  • OpenAI API Keys
  • GitHub Personal Access Tokens
  • AWS Access Keys
  • AWS Secret Access Keys
  • Google API Keys
  • Google OAuth Tokens
  • Stripe Secret Keys
  • Stripe Restricted Keys
  • Twilio API Keys
  • Slack Tokens
  • Discord Bot Tokens
  • Firebase Cloud Messaging Server Keys
  • SendGrid API Keys

Database Credentials

  • MongoDB URIs
  • PostgreSQL URIs
  • MySQL URIs
  • Redis URIs

Authentication & Secrets

  • JWT Tokens
  • Bearer Tokens
  • Hardcoded Passwords
  • Hardcoded Secrets
  • Hardcoded API Keys
  • Hardcoded Token Variables

Private Keys & Certificates

  • RSA Private Keys
  • EC Private Keys
  • DSA Private Keys
  • OpenSSH Private Keys
  • PGP Private Keys
  • X.509 Certificates

Cloud Credentials

  • Azure Storage Connection Strings
  • Heroku API Keys

Project Structure

SafeCommit/
│
├── src/
│   └── safecommit/
│       ├── __init__.py
│       ├── cli.py
│       ├── scanner.py
│       ├── patterns.py
│       └── utils.py
│
├── tests/
├── README.md
├── CHANGELOG.md
├── LICENSE
├── pyproject.toml
└── .gitignore

Contributing

Contributions, bug reports, feature requests, and improvements are welcome.

If you'd like to contribute, feel free to open an issue or submit a pull request.


License

This project is licensed under the MIT License.


Author

Sushant Kumar Kushwaha

GitHub: https://github.com/sushantkr1187

Metadata

Release files for safecommit-cli 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for safecommit-cli 1.0.1
File Size Uploaded
safecommit_cli-1.0.1.tar.gz 9.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for safecommit-cli 1.0.1
File Interpreter ABI Platform
safecommit_cli-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 19.6 kB

Release files / safecommit_cli-1.0.1.tar.gz

Download URL safecommit_cli-1.0.1.tar.gz
Size 9.9 kB
Tags Source
SHA-256 checksum
How to use checksums
69bf2e621a3d3720e95ee94d65aea1567fca498b1555374a04abc319d6b03452
BLAKE2b-256 checksum
How to use checksums
c4dda506ee922a1af9efbaf67c04e4718099a64b98958a3c4b8ba900b5b21e68
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.3

Release files / safecommit_cli-1.0.1-py3-none-any.whl

Download URL safecommit_cli-1.0.1-py3-none-any.whl
Size 9.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2750fb07126f5eedf52579fa6dd9738d833d0eda8107becab6f3baf8d7b0d18b
BLAKE2b-256 checksum
How to use checksums
83865cfb806308fa3f9cb907855641a4db5003f5456dc775f16cef04edfe2d6f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.3

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page