Skip to main content

SecretSieve

SecretSieve icon

Sieve the secrets out of your source.

SecretSieve is a professional, intelligent, local-first secret detection CLI written in Python. It scans source code, configuration files, and project directories for accidentally exposed credentials - API keys, tokens, private keys, passwords, and connection strings - using a multi-signal engine (signatures + entropy + context + deterministic confidence/severity scoring), not just regex.

Copyright © 3rabDev - https://3rabdev.online

License: MIT - see LICENSE. Copyright © 3rabDev.

Privacy

  • 100% local by default. No network I/O during scanning, no uploads, no telemetry.
  • Secrets are never verified against third-party services (that would transmit them).
  • All output is redacted by default (AKIA****************9X2F).

Install

Requires Python 3.10+.

pip install secretsieve        # from PyPI (once released)
pipx install secretsieve       # isolated CLI install (recommended)
pip install -e .               # from source (developers)

Quick start

secretsieve .                                  # scan the current project
secretsieve ./src config.py                    # scan specific paths
secretsieve scan . --json --fail-on high       # CI-friendly JSON gate
secretsieve rules --list                       # show all detection rules
secretsieve explain SS-GITHUB-001              # understand a rule
secretsieve config --init > secretsieve.toml   # starter config

Exit codes (generic CI)

Code Meaning
0 No findings at or above --fail-on
1 Findings at or above --fail-on
2 Scanner / configuration error

--fail-on defaults to low (any LOW+ fails; INFO never fails). --severity only controls display; hidden findings still fail CI.

Suppressing a false positive

Preferred order:

  1. Verify it really is a false positive (placeholder? hash? test data?).
  2. Suppress by fingerprint (stable, auditable) in secretsieve.toml:
    [[allow.fingerprint]]
    value = "sha256:..."
    
  3. Or scope a rule+path:
    [[allow.path_rule]]
    rule = "SS-GENERIC-002"
    path = "tests/fixtures/**"
    
  4. Or add a same-line comment (line scope only, visible in diffs):
    password = "not-a-real-secret-for-tests"  # secretsieve:ignore
    

Documentation

Metadata

Release files for secretsieve 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secretsieve 1.0.0
File Size Uploaded
secretsieve-1.0.0.tar.gz 2.3 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for secretsieve 1.0.0
File Interpreter ABI Platform
secretsieve-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.4 MB

Release files / secretsieve-1.0.0.tar.gz

Download URL secretsieve-1.0.0.tar.gz
Size 2.3 MB
Tags Source
SHA-256 checksum
How to use checksums
caa435a87310861c2f9cc25983f1440bcdf7db0d258febcd5544ceddc6c12638
BLAKE2b-256 checksum
How to use checksums
ca47da0b0a9588d7ab7484bdee6dff619878074fc4a2735c104e45b59d0bac64
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.8

Release files / secretsieve-1.0.0-py3-none-any.whl

Download URL secretsieve-1.0.0-py3-none-any.whl
Size 65.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bc7f0c90a6707fedd3876f7c3924b085d705961c139309c623ac4bc53a28a1a9
BLAKE2b-256 checksum
How to use checksums
6e607e5d02bc1357159f54fe2a1a23053a5eb1c063720541dedd3d197ab72b3f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.8

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page