SecretSieve
Sieve the secrets out of your source.
SecretSieve is a professional, intelligent, local-first secret detection CLI written in Python. It scans source code, configuration files, and project directories for accidentally exposed credentials - API keys, tokens, private keys, passwords, and connection strings - using a multi-signal engine (signatures + entropy + context + deterministic confidence/severity scoring), not just regex.
Copyright © 3rabDev - https://3rabdev.online
License: MIT - see LICENSE. Copyright © 3rabDev.
Privacy
- 100% local by default. No network I/O during scanning, no uploads, no telemetry.
- Secrets are never verified against third-party services (that would transmit them).
- All output is redacted by default (
AKIA****************9X2F).
Install
Requires Python 3.10+.
pip install secretsieve # from PyPI (once released)
pipx install secretsieve # isolated CLI install (recommended)
pip install -e . # from source (developers)
Quick start
secretsieve . # scan the current project
secretsieve ./src config.py # scan specific paths
secretsieve scan . --json --fail-on high # CI-friendly JSON gate
secretsieve rules --list # show all detection rules
secretsieve explain SS-GITHUB-001 # understand a rule
secretsieve config --init > secretsieve.toml # starter config
Exit codes (generic CI)
| Code | Meaning |
|---|---|
0 |
No findings at or above --fail-on |
1 |
Findings at or above --fail-on |
2 |
Scanner / configuration error |
--fail-on defaults to low (any LOW+ fails; INFO never fails).
--severity only controls display; hidden findings still fail CI.
Suppressing a false positive
Preferred order:
- Verify it really is a false positive (placeholder? hash? test data?).
- Suppress by fingerprint (stable, auditable) in
secretsieve.toml:[[allow.fingerprint]] value = "sha256:..."
- Or scope a rule+path:
[[allow.path_rule]] rule = "SS-GENERIC-002" path = "tests/fixtures/**"
- Or add a same-line comment (line scope only, visible in diffs):
password = "not-a-real-secret-for-tests" # secretsieve:ignore
Documentation
- Architecture · CLI reference · Install · Quick start · Configuration · Detection coverage · False positives · Privacy · Security · Contributing · Release process · Performance
- Master engineering blueprint: PLAN.md
- Changes: CHANGELOG.md
Metadata
Release files for secretsieve 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secretsieve-1.0.0.tar.gz | 2.3 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| secretsieve-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.4 MB
Release files / secretsieve-1.0.0.tar.gz
| Download URL | secretsieve-1.0.0.tar.gz |
|---|---|
| Size | 2.3 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
caa435a87310861c2f9cc25983f1440bcdf7db0d258febcd5544ceddc6c12638
|
|
BLAKE2b-256 checksum How to use checksums |
ca47da0b0a9588d7ab7484bdee6dff619878074fc4a2735c104e45b59d0bac64
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.8
|
Release files / secretsieve-1.0.0-py3-none-any.whl
| Download URL | secretsieve-1.0.0-py3-none-any.whl |
|---|---|
| Size | 65.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
bc7f0c90a6707fedd3876f7c3924b085d705961c139309c623ac4bc53a28a1a9
|
|
BLAKE2b-256 checksum How to use checksums |
6e607e5d02bc1357159f54fe2a1a23053a5eb1c063720541dedd3d197ab72b3f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.8
|