sealscan
Scan before you ship. A local-only command line scanner that finds hardcoded secrets, insecure code patterns and risky open-source licenses in one pass.
- 100% local. No network calls, no telemetry, no accounts. Files are read in memory and nothing is uploaded or stored.
- Zero dependencies. Standard library only.
- One engine for two problems. Leaked secrets (API keys, tokens, private keys) and commercially risky licenses (AGPL, GPL, SSPL, ...) in a single scan.
- CI friendly. Exit codes, JSON and SARIF output, pre-commit hook.
Install
pip install sealscan
From source:
git clone <your-repo-url>
cd sealscan
pip install -e .
Requires Python 3.9 or newer.
Usage
sealscan . # scan the current directory
sealscan path/to/project # scan another directory
sealscan app.py # scan a single file
sealscan . --min-severity high # hide low and medium findings
sealscan . --only secret,license # choose categories
sealscan . --format json # json output (also: sarif, text)
sealscan . -f sarif -o results.sarif
sealscan --list-rules # show every rule and its id
Example output:
[CRITICAL] SECRET-AWS-ACCESS-KEY src/app.py:2
AWS access key ID found
> AKIA******LE
[HIGH] LICENSE-GPL package.json:1
Project declares this license
> GPL-3.0
sealscan: scanned 5 files, 2 issues (critical: 1, high: 1)
Secret values are always redacted in every output format.
What it detects
| Category | Examples |
|---|---|
secret |
AWS, GitHub, GitLab, Slack, Stripe, Google, SendGrid, npm, OpenAI and Anthropic keys, private key blocks, JWTs, passwords in URLs, hardcoded credentials, committed .env and key files |
vulnerability |
eval/exec, shell=True, os.system, unsafe pickle/yaml.load, weak hashes, disabled TLS verification, SQL built with string formatting, JavaScript innerHTML, document.write, child_process.exec |
license |
AGPL, SSPL, GPL, LGPL, EUPL, BUSL and NonCommercial licenses found in LICENSE files, SPDX headers, and package.json, composer.json, pyproject.toml, setup.py, setup.cfg, Cargo.toml |
Run sealscan --list-rules for the full list.
Ignoring files and findings
.gitignorefiles are respected automatically (including nested ones). Use--no-gitignoreto scan ignored files too.- Add a
.sealscanignorefile (same syntax as.gitignore) for extra excludes. - Silence one line with a comment:
# sealscan:ignore(or// sealscan:ignore). - Common folders such as
.git,node_modules,.venvanddistare skipped.
Configuration
Create .sealscan.json in the directory you scan (or pass --config FILE):
{
"ignore": ["tests/", "vendor/"],
"disable_rules": ["VULN-PY-WEAK-HASH"],
"min_severity": "low",
"fail_on": "high"
}
Command line flags override the config file.
Exit codes
| Code | Meaning |
|---|---|
| 0 | No finding at or above --fail-on (default: high) |
| 1 | At least one finding at or above --fail-on |
| 2 | Usage or configuration error |
Severities, lowest to highest: low, medium, high, critical.
Use in CI and Git
pre-commit (.pre-commit-config.yaml):
repos:
- repo: <your-repo-url>
rev: v0.1.0
hooks:
- id: sealscan
GitHub Actions (after the package is published to PyPI):
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: pip install sealscan
- run: sealscan . --fail-on high
GitHub code scanning (findings appear in the Security tab):
- run: sealscan . --format sarif --output sealscan.sarif --fail-on critical
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: sealscan.sarif
Limitations
sealscan is pattern based, so it is fast and fully offline but not perfect.
Expect some false positives (use sealscan:ignore or the config file) and
some misses. License detection covers declared licenses in your own project;
it does not resolve the licenses of your installed dependencies. Treat it as a
safety net, not a guarantee.
Development
pip install -e .
python -m unittest discover -v
sealscan .
License
MIT
Metadata
Release files for sealscan 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sealscan-0.1.0.tar.gz | 20.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sealscan-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 38.6 kB
Release files / sealscan-0.1.0.tar.gz
| Download URL | sealscan-0.1.0.tar.gz |
|---|---|
| Size | 20.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6b4674918955404827801d25ec95c69f554d169bedf77ccee484f39ec3356e39
|
|
BLAKE2b-256 checksum How to use checksums |
525a671b957bec7e9bea91b1b51a3f62ad36c146d966aca1d3b00d07eb0573a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / sealscan-0.1.0-py3-none-any.whl
| Download URL | sealscan-0.1.0-py3-none-any.whl |
|---|---|
| Size | 18.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
77fa09fd041839e8972969fdff242a86a03ef77a1d403e5eb715c590578b57cd
|
|
BLAKE2b-256 checksum How to use checksums |
bc65f529b23dfb2802ded0451ce83f5be92a97a078de6425f4f7d002c20be75a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|