Skip to main content

sealscan

Scan before you ship. A local-only command line scanner that finds hardcoded secrets, insecure code patterns and risky open-source licenses in one pass.

  • 100% local. No network calls, no telemetry, no accounts. Files are read in memory and nothing is uploaded or stored.
  • Zero dependencies. Standard library only.
  • One engine for two problems. Leaked secrets (API keys, tokens, private keys) and commercially risky licenses (AGPL, GPL, SSPL, ...) in a single scan.
  • CI friendly. Exit codes, JSON and SARIF output, pre-commit hook.

Install

pip install sealscan

From source:

git clone <your-repo-url>
cd sealscan
pip install -e .

Requires Python 3.9 or newer.

Usage

sealscan .                          # scan the current directory
sealscan path/to/project            # scan another directory
sealscan app.py                     # scan a single file
sealscan . --min-severity high      # hide low and medium findings
sealscan . --only secret,license    # choose categories
sealscan . --format json            # json output (also: sarif, text)
sealscan . -f sarif -o results.sarif
sealscan --list-rules               # show every rule and its id

Example output:

[CRITICAL] SECRET-AWS-ACCESS-KEY  src/app.py:2
    AWS access key ID found
    > AKIA******LE
[HIGH] LICENSE-GPL  package.json:1
    Project declares this license
    > GPL-3.0

sealscan: scanned 5 files, 2 issues (critical: 1, high: 1)

Secret values are always redacted in every output format.

What it detects

Category Examples
secret AWS, GitHub, GitLab, Slack, Stripe, Google, SendGrid, npm, OpenAI and Anthropic keys, private key blocks, JWTs, passwords in URLs, hardcoded credentials, committed .env and key files
vulnerability eval/exec, shell=True, os.system, unsafe pickle/yaml.load, weak hashes, disabled TLS verification, SQL built with string formatting, JavaScript innerHTML, document.write, child_process.exec
license AGPL, SSPL, GPL, LGPL, EUPL, BUSL and NonCommercial licenses found in LICENSE files, SPDX headers, and package.json, composer.json, pyproject.toml, setup.py, setup.cfg, Cargo.toml

Run sealscan --list-rules for the full list.

Ignoring files and findings

  • .gitignore files are respected automatically (including nested ones). Use --no-gitignore to scan ignored files too.
  • Add a .sealscanignore file (same syntax as .gitignore) for extra excludes.
  • Silence one line with a comment: # sealscan:ignore (or // sealscan:ignore).
  • Common folders such as .git, node_modules, .venv and dist are skipped.

Configuration

Create .sealscan.json in the directory you scan (or pass --config FILE):

{
  "ignore": ["tests/", "vendor/"],
  "disable_rules": ["VULN-PY-WEAK-HASH"],
  "min_severity": "low",
  "fail_on": "high"
}

Command line flags override the config file.

Exit codes

Code Meaning
0 No finding at or above --fail-on (default: high)
1 At least one finding at or above --fail-on
2 Usage or configuration error

Severities, lowest to highest: low, medium, high, critical.

Use in CI and Git

pre-commit (.pre-commit-config.yaml):

repos:
  - repo: <your-repo-url>
    rev: v0.1.0
    hooks:
      - id: sealscan

GitHub Actions (after the package is published to PyPI):

- uses: actions/setup-python@v5
  with:
    python-version: "3.12"
- run: pip install sealscan
- run: sealscan . --fail-on high

GitHub code scanning (findings appear in the Security tab):

- run: sealscan . --format sarif --output sealscan.sarif --fail-on critical
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: sealscan.sarif

Limitations

sealscan is pattern based, so it is fast and fully offline but not perfect. Expect some false positives (use sealscan:ignore or the config file) and some misses. License detection covers declared licenses in your own project; it does not resolve the licenses of your installed dependencies. Treat it as a safety net, not a guarantee.

Development

pip install -e .
python -m unittest discover -v
sealscan .

License

MIT

Metadata

Release files for sealscan 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sealscan 0.1.0
File Size Uploaded
sealscan-0.1.0.tar.gz 20.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sealscan 0.1.0
File Interpreter ABI Platform
sealscan-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 38.6 kB

Release files / sealscan-0.1.0.tar.gz

Download URL sealscan-0.1.0.tar.gz
Size 20.5 kB
Tags Source
SHA-256 checksum
How to use checksums
6b4674918955404827801d25ec95c69f554d169bedf77ccee484f39ec3356e39
BLAKE2b-256 checksum
How to use checksums
525a671b957bec7e9bea91b1b51a3f62ad36c146d966aca1d3b00d07eb0573a1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / sealscan-0.1.0-py3-none-any.whl

Download URL sealscan-0.1.0-py3-none-any.whl
Size 18.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
77fa09fd041839e8972969fdff242a86a03ef77a1d403e5eb715c590578b57cd
BLAKE2b-256 checksum
How to use checksums
bc65f529b23dfb2802ded0451ce83f5be92a97a078de6425f4f7d002c20be75a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page