SecSentry
A Git incident scanner for leaked secrets. It searches the working tree and the full commit history, deduplicates by blob so the same object is never scanned twice, and reports every finding as a case file: what leaked, where, who introduced it, whether it is still in HEAD, and how to revoke it.
Values are always masked. SecSentry never sends a credential to a vendor API to check whether it still works.
This PyPI package is a PATH wrapper. The detectors live in the Go binary.
pip install secsentrygives you thesecsentryconsole script; that script still needs the Go CLI onPATH.
Install
# 1. Engine (required)
go install github.com/umeraamir69/secsentry/cmd/secsentry@latest
# or download a binary from GitHub Releases: linux / macOS / Windows
# 2. This wrapper (optional — only if you want `pip` / `uv` on PATH)
pip install secsentry
secsentry --version
secsentry scan .
If the Go binary is missing, the wrapper prints the go install line and exits 1. It does not reimplement any detectors.
Usage
secsentry scan . # working tree
secsentry scan . --history # every commit
secsentry scan --staged # index only
secsentry scan . --severity high
secsentry scan . --type aws --type github
secsentry scan . --format json -o out.json
secsentry scan . --format html -o report.html
secsentry scan . --format sarif -o secsentry.sarif
secsentry serve . --history # dashboard, 127.0.0.1 only
secsentry install-hook # block commits that stage secrets
Exit code is 1 when a finding reaches --fail-on (default high), otherwise 0.
What you get
| Layer | Behaviour |
|---|---|
| Scanner | Working tree, staged diff, or full history. Each unique blob OID is read once. Decodes base64 / hex / percent and walks zip / tar / gz. |
| Detectors | AWS, GitHub, OpenAI, Anthropic, Google, Stripe, Slack, Discord, Telegram, Azure storage, Datadog, DigitalOcean, xAI, Perplexity, private keys, JWTs, Basic auth, database URLs, labeled API_KEY= / PASSWORD= with Shannon entropy. |
| Verification | Prefix, length, and format checks locally. No network calls. |
| Reporting | Terminal, JSON, SARIF, HTML, localhost dashboard. Masked everywhere. Location (path:line:column) is always shown. |
| Enforcement | Pre-commit hook and a GitHub Action. |
You cannot rotate what you cannot find, so every report shows path, commit, and author. What it never shows is a pasteable credential. Duplicates are tracked by SHA-256 fingerprint; the allowlist (.secsentryallow) accepts fingerprints, never raw secrets.
GitHub Action
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: umeraamir69/secsentry@v1.0.0
with:
history: true
fail-on: high
Links
- Source and full README: github.com/umeraamir69/secsentry
- Releases / binaries: GitHub Releases
- npm wrapper: npmjs.com/package/secsentry
- Demo leak repo: umeraamir69/testKeys
License
MIT. Every credential in the tests, the demo repo, and the eval corpus is fake.
Metadata
Release files for secsentry 1.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| secsentry-1.4.0.tar.gz | 8.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| secsentry-1.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.9 kB
Release files / secsentry-1.4.0.tar.gz
| Download URL | secsentry-1.4.0.tar.gz |
|---|---|
| Size | 8.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e28040d4c49c834a833233fe58b837cff4679737123a649c2650d48f49bb851f
|
|
BLAKE2b-256 checksum How to use checksums |
3ef54716621f242e505a73509c25277075a2e53e67148f6266dedb188243bf81
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency logRelease files / secsentry-1.4.0-py3-none-any.whl
| Download URL | secsentry-1.4.0-py3-none-any.whl |
|---|---|
| Size | 5.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b08a789616c5890313ae46cf6f7fd02cea1ad90584326bb9db3cc28d9355bb04
|
|
BLAKE2b-256 checksum How to use checksums |
43f3a943957793e3e148c4613f5f258ffcefe7cfb9546a8fbfe43d9828dcad12
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.
Transparency log