🔍 shadowGIT
Automated detection of dangling commits in Git repositories
Identifies commits that were force-pushed away but remain accessible, potentially exposing sensitive data.
✨ Features
- 🔎 Repository Scanning - Scan specific repositories for dangling commits
- 👤 User Activity Analysis - Scan all repositories for a GitHub user
- 📊 JSON Output - Machine-readable output format
- 🚀 Fast & Efficient - Quick detection of exposed commits
- 🔒 Security Focused - Helps identify potential secret leaks
📦 Installation
pip install shadowgit
🚀 Quick Start
Scan a specific repository
shadowGIT github -r owner/repo
Scan all repositories for a user
shadowGIT github -u username
JSON output format
shadowGIT github -r owner/repo --json
shadowGIT github -u username --json
📋 Output Examples
Standard Output
[+] Scanning GitHub repo: owner/repo
[!] Found dangling commit: 0ae67fe748e0b6ca52066e76611f4237a0ace744
JSON Output
{
"repository": "owner/repo",
"commit_sha": "0ae67fe748e0b6ca52066e76611f4237a0ace744",
"author": {
"name": "Author Name",
"email": "author@example.com"
},
"message": "Commit message",
"secrets_found": [],
"url": "https://github.com/owner/repo/commit/0ae67fe748e0b6ca52066e76611f4237a0ace744"
}
🔧 How It Works
shadowGIT analyzes GitHub push events and checks if commits are still accessible via branch history. Commits that were force-pushed away but remain in the repository are flagged as dangling commits.
The tool detects commits that show GitHub's spoofed commit warning, indicating they exist in the repository but are not part of any branch's history.
📋 Requirements
- Python 3.11 or higher
- GitHub API access (no authentication required for public repositories)
📝 License
MIT License - see LICENSE file for details
Metadata
Release files for shadowgit 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| shadowgit-0.1.2.tar.gz | 7.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| shadowgit-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.9 kB
Release files / shadowgit-0.1.2.tar.gz
| Download URL | shadowgit-0.1.2.tar.gz |
|---|---|
| Size | 7.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3ed988ae4b3dc2512274369f66e9927f6cf047f49ffa0efd9ce7c86e0f8d34a4
|
|
BLAKE2b-256 checksum How to use checksums |
a4da8b40c01b46f3f51ce518ee8b4a27d8d6de82a4b6cec1b47b6a946870767b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.
Transparency logRelease files / shadowgit-0.1.2-py3-none-any.whl
| Download URL | shadowgit-0.1.2-py3-none-any.whl |
|---|---|
| Size | 7.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9860918876e3d45236876de7ce2f750b228dddcf1152ab42a327cb7f23b3a9a1
|
|
BLAKE2b-256 checksum How to use checksums |
8612aa4c50f287cc884edbf6eda07c6711de893800887f4be82fdd935826afcc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 12, 2026.
Transparency log