SafeCommit
A lightweight, cross-platform Python CLI that scans projects for exposed API keys, credentials, tokens, connection strings, private keys, and other sensitive information before you commit.
Prevent accidentally leaking secrets to Git repositories with fast, recursive, regex-based scanning.
Features
- 🔍 Detects 25+ common secret types
- 📂 Recursive project scanning
- ⚡ Fast regex-based detection
- 🖥️ Cross-platform (Windows, Linux, macOS)
- 🎨 Beautiful terminal output powered by Rich
- 📄 Reports file path, line number, severity, matched pattern, and matched value
- 📦 Lightweight with zero external services
- 🚀 Simple installation using
pip
Installation
Install from PyPI:
pip install safecommit-cli
Verify installation:
safecommit --version
Quick Start
Scan the current project:
safecommit scan .
Scan another directory:
safecommit scan /path/to/project
Example:
safecommit scan D:\Projects\MyApp
Example Output
Scanning: D:\Projects\MyApp
Found 2 potential issue(s).
╭──────────── Secret Detected ────────────╮
│ File : backend/config.py │
│ Line : 18 │
│ Severity : HIGH │
│ Pattern : OpenAI API Key │
│ Match : sk-proj-**************** │
╰─────────────────────────────────────────╯
Supported Secret Types
API Keys & Tokens
- OpenAI API Keys
- GitHub Personal Access Tokens
- AWS Access Keys
- AWS Secret Access Keys
- Google API Keys
- Google OAuth Tokens
- Stripe Secret Keys
- Stripe Restricted Keys
- Twilio API Keys
- Slack Tokens
- Discord Bot Tokens
- Firebase Cloud Messaging Server Keys
- SendGrid API Keys
Database Credentials
- MongoDB URIs
- PostgreSQL URIs
- MySQL URIs
- Redis URIs
Authentication & Secrets
- JWT Tokens
- Bearer Tokens
- Hardcoded Passwords
- Hardcoded Secrets
- Hardcoded API Keys
- Hardcoded Token Variables
Private Keys & Certificates
- RSA Private Keys
- EC Private Keys
- DSA Private Keys
- OpenSSH Private Keys
- PGP Private Keys
- X.509 Certificates
Cloud Credentials
- Azure Storage Connection Strings
- Heroku API Keys
Project Structure
SafeCommit/
│
├── src/
│ └── safecommit/
│ ├── __init__.py
│ ├── cli.py
│ ├── scanner.py
│ ├── patterns.py
│ └── utils.py
│
├── tests/
├── README.md
├── CHANGELOG.md
├── LICENSE
├── pyproject.toml
└── .gitignore
Contributing
Contributions, bug reports, feature requests, and improvements are welcome.
If you'd like to contribute, feel free to open an issue or submit a pull request.
License
This project is licensed under the MIT License.
Author
Sushant Kumar Kushwaha
GitHub: https://github.com/sushantkr1187
Metadata
Release files for safecommit-cli 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| safecommit_cli-1.0.1.tar.gz | 9.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| safecommit_cli-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 19.6 kB
Release files / safecommit_cli-1.0.1.tar.gz
| Download URL | safecommit_cli-1.0.1.tar.gz |
|---|---|
| Size | 9.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
69bf2e621a3d3720e95ee94d65aea1567fca498b1555374a04abc319d6b03452
|
|
BLAKE2b-256 checksum How to use checksums |
c4dda506ee922a1af9efbaf67c04e4718099a64b98958a3c4b8ba900b5b21e68
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|
Release files / safecommit_cli-1.0.1-py3-none-any.whl
| Download URL | safecommit_cli-1.0.1-py3-none-any.whl |
|---|---|
| Size | 9.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2750fb07126f5eedf52579fa6dd9738d833d0eda8107becab6f3baf8d7b0d18b
|
|
BLAKE2b-256 checksum How to use checksums |
83865cfb806308fa3f9cb907855641a4db5003f5456dc775f16cef04edfe2d6f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|