simple-detect-secrets
simple-detect-secrets tries to find secrets (passwords, auth tokens) in a codebase.
In git repositories, simple-detect-secrets only scans checked-in files.
Otherwise it scans all files.
Diagnostics go to stderr, with the scan mode and file count on one line:
No git repository detected: Scanning all files (2 files) or
Detected git repository: Scanning only Git-tracked files (2 files).
Empty scans report No files detected (0 files).
Running
Simply run
uvx simple-detect-secrets
in a directory to search for possible secrets.
Findings go to stdout in filename:lineno:full source line format, like grep.
Each matching line appears once, preserving its indentation and spacing.
Exclude files or directories with repeatable, quoted glob patterns:
uvx simple-detect-secrets --exclude '*.log' --exclude 'vendor/*' --exclude '.venv'
Developing
uv sync --locked
uv run simple-detect-secrets
uv run pytest tests
Build the source distribution and wheel with uv build. Install the optional
word-list support with uv sync --extra word_list.
Caveats
This is not meant to be a sure-fire solution to prevent secrets from entering the codebase. Only proper developer education can truly do that. This pre-commit hook merely implements several heuristics to try and prevent obvious cases of committing secrets.
Things that won't be prevented
- Multi-line secrets
- Default passwords that don't trigger the
KeywordDetector(e.g.login = "hunter2")
Notes
This is an old fork of Yelp's detect-secrets.
This is a command line tool:
- never calls the network
- doesn't obfuscate/hash the secrets that it finds
- doesn't have plugins
Metadata
Release files for simple-detect-secrets 0.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| simple_detect_secrets-0.0.3.tar.gz | 41.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| simple_detect_secrets-0.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 100.5 kB
Release files / simple_detect_secrets-0.0.3.tar.gz
| Download URL | simple_detect_secrets-0.0.3.tar.gz |
|---|---|
| Size | 41.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
afeb9ec696bc969f89c0d21ce187612ccc317cd433fce43e504344dd35b2e84c
|
|
BLAKE2b-256 checksum How to use checksums |
3503f2ad9be6bf45ad2de16ee64dd722923937f897725dc13a6cd287925857ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.8 {"installer":{"name":"uv","version":"0.10.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / simple_detect_secrets-0.0.3-py3-none-any.whl
| Download URL | simple_detect_secrets-0.0.3-py3-none-any.whl |
|---|---|
| Size | 58.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
65b68ee1fd2ad3a46f1995fce8717b7ffe1420ff3cd848419c95080b8f184c4c
|
|
BLAKE2b-256 checksum How to use checksums |
5cb8e56d41581baf1c5b9453c9beb5ba6eea9da6a1eee1b2bf35a1724e25b781
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.8 {"installer":{"name":"uv","version":"0.10.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|