Skip to main content

🔍 shadowGIT

Automated detection of dangling commits in Git repositories

Python 3.11+ Version License

Identifies commits that were force-pushed away but remain accessible, potentially exposing sensitive data.


✨ Features

  • 🔎 Repository Scanning - Scan specific repositories for dangling commits
  • 👤 User Activity Analysis - Scan all repositories for a GitHub user
  • 📊 JSON Output - Machine-readable output format
  • 🚀 Fast & Efficient - Quick detection of exposed commits
  • 🔒 Security Focused - Helps identify potential secret leaks

📦 Installation

pip install shadowgit

🚀 Quick Start

Scan a specific repository

shadowGIT github -r owner/repo

Scan all repositories for a user

shadowGIT github -u username

JSON output format

shadowGIT github -r owner/repo --json
shadowGIT github -u username --json

📋 Output Examples

Standard Output

[+] Scanning GitHub repo: owner/repo
[!] Found dangling commit: 0ae67fe748e0b6ca52066e76611f4237a0ace744

JSON Output

{
  "repository": "owner/repo",
  "commit_sha": "0ae67fe748e0b6ca52066e76611f4237a0ace744",
  "author": {
    "name": "Author Name",
    "email": "author@example.com"
  },
  "message": "Commit message",
  "secrets_found": [],
  "url": "https://github.com/owner/repo/commit/0ae67fe748e0b6ca52066e76611f4237a0ace744"
}

🔧 How It Works

shadowGIT analyzes GitHub push events and checks if commits are still accessible via branch history. Commits that were force-pushed away but remain in the repository are flagged as dangling commits.

The tool detects commits that show GitHub's spoofed commit warning, indicating they exist in the repository but are not part of any branch's history.

📋 Requirements

  • Python 3.11 or higher
  • GitHub API access (no authentication required for public repositories)

📝 License

MIT License - see LICENSE file for details

Metadata

Release files for shadowgit 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for shadowgit 0.1.2
File Size Uploaded
shadowgit-0.1.2.tar.gz 7.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for shadowgit 0.1.2
File Interpreter ABI Platform
shadowgit-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 14.9 kB

Release files / shadowgit-0.1.2.tar.gz

Download URL shadowgit-0.1.2.tar.gz
Size 7.6 kB
Tags Source
SHA-256 checksum
How to use checksums
3ed988ae4b3dc2512274369f66e9927f6cf047f49ffa0efd9ce7c86e0f8d34a4
BLAKE2b-256 checksum
How to use checksums
a4da8b40c01b46f3f51ce518ee8b4a27d8d6de82a4b6cec1b47b6a946870767b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.

Transparency log

Release files / shadowgit-0.1.2-py3-none-any.whl

Download URL shadowgit-0.1.2-py3-none-any.whl
Size 7.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9860918876e3d45236876de7ce2f750b228dddcf1152ab42a327cb7f23b3a9a1
BLAKE2b-256 checksum
How to use checksums
8612aa4c50f287cc884edbf6eda07c6711de893800887f4be82fdd935826afcc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page