Skip to main content

SecSentry

A Git incident scanner for leaked secrets. It searches the working tree and the full commit history, deduplicates by blob so the same object is never scanned twice, and reports every finding as a case file: what leaked, where, who introduced it, whether it is still in HEAD, and how to revoke it.

Values are always masked. SecSentry never sends a credential to a vendor API to check whether it still works.

This PyPI package is a PATH wrapper. The detectors live in the Go binary. pip install secsentry gives you the secsentry console script; that script still needs the Go CLI on PATH.

Install

# 1. Engine (required)
go install github.com/umeraamir69/secsentry/cmd/secsentry@latest
# or download a binary from GitHub Releases: linux / macOS / Windows

# 2. This wrapper (optional — only if you want `pip` / `uv` on PATH)
pip install secsentry

secsentry --version
secsentry scan .

If the Go binary is missing, the wrapper prints the go install line and exits 1. It does not reimplement any detectors.

Usage

secsentry scan .                          # working tree
secsentry scan . --history                # every commit
secsentry scan --staged                   # index only
secsentry scan . --severity high
secsentry scan . --type aws --type github
secsentry scan . --format json -o out.json
secsentry scan . --format html -o report.html
secsentry scan . --format sarif -o secsentry.sarif
secsentry serve . --history               # dashboard, 127.0.0.1 only

secsentry install-hook                    # block commits that stage secrets

Exit code is 1 when a finding reaches --fail-on (default high), otherwise 0.

What you get

Layer Behaviour
Scanner Working tree, staged diff, or full history. Each unique blob OID is read once. Decodes base64 / hex / percent and walks zip / tar / gz.
Detectors AWS, GitHub, OpenAI, Anthropic, Google, Stripe, Slack, Discord, Telegram, Azure storage, Datadog, DigitalOcean, xAI, Perplexity, private keys, JWTs, Basic auth, database URLs, labeled API_KEY= / PASSWORD= with Shannon entropy.
Verification Prefix, length, and format checks locally. No network calls.
Reporting Terminal, JSON, SARIF, HTML, localhost dashboard. Masked everywhere. Location (path:line:column) is always shown.
Enforcement Pre-commit hook and a GitHub Action.

You cannot rotate what you cannot find, so every report shows path, commit, and author. What it never shows is a pasteable credential. Duplicates are tracked by SHA-256 fingerprint; the allowlist (.secsentryallow) accepts fingerprints, never raw secrets.

GitHub Action

- uses: actions/checkout@v4
  with:
    fetch-depth: 0
- uses: umeraamir69/secsentry@v1.0.0
  with:
    history: true
    fail-on: high

Links

License

MIT. Every credential in the tests, the demo repo, and the eval corpus is fake.

Metadata

Release files for secsentry 1.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secsentry 1.4.0
File Size Uploaded
secsentry-1.4.0.tar.gz 8.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secsentry 1.4.0
File Interpreter ABI Platform
secsentry-1.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.9 kB

Release files / secsentry-1.4.0.tar.gz

Download URL secsentry-1.4.0.tar.gz
Size 8.7 kB
Tags Source
SHA-256 checksum
How to use checksums
e28040d4c49c834a833233fe58b837cff4679737123a649c2650d48f49bb851f
BLAKE2b-256 checksum
How to use checksums
3ef54716621f242e505a73509c25277075a2e53e67148f6266dedb188243bf81
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log

Release files / secsentry-1.4.0-py3-none-any.whl

Download URL secsentry-1.4.0-py3-none-any.whl
Size 5.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b08a789616c5890313ae46cf6f7fd02cea1ad90584326bb9db3cc28d9355bb04
BLAKE2b-256 checksum
How to use checksums
43f3a943957793e3e148c4613f5f258ffcefe7cfb9546a8fbfe43d9828dcad12
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.4.0 This release

2 release files

1.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page