simple-detect-secrets
simple-detect-secrets tries to find secrets (passwords, auth tokens) in a codebase.
In git repositories, simple-detect-secrets only scans checked-in files.
Otherwise it scans all files.
Diagnostics go to stderr, with the scan mode and file count on one line:
No git repository detected: Scanning all files (2 files) or
Detected git repository: Scanning only Git-tracked files (2 files).
Empty scans report No files detected (0 files).
Running
Simply run
uvx simple-detect-secrets
in a directory to search for possible secrets.
Exclude files or directories with repeatable, quoted glob patterns:
uvx simple-detect-secrets --exclude '*.log' --exclude 'vendor/*' --exclude '.venv'
Developing
uv sync --locked
uv run simple-detect-secrets
uv run pytest tests
Build the source distribution and wheel with uv build. Install the optional
word-list support with uv sync --extra word_list.
Profiling
Use uvx simple-detect-secrets --profile to report elapsed seconds spent in
each enabled detector, summed across files and listed slowest first. The report
goes to stderr. Timings include each detector's file reading and parsing, but
exclude file discovery, detector initialization, and result formatting.
Profiling also works with --string and --update.
Caveats
This is not meant to be a sure-fire solution to prevent secrets from entering the codebase. Only proper developer education can truly do that. This pre-commit hook merely implements several heuristics to try and prevent obvious cases of committing secrets.
Things that won't be prevented
- Multi-line secrets
- Default passwords that don't trigger the
KeywordDetector(e.g.login = "hunter2")
Notes
This is an old fork of Yelp's detect-secrets.
This is a command line tool:
- never calls the network
- doesn't obfuscate/hash the secrets that it finds
- doesn't have plugins
Metadata
Release files for simple-detect-secrets 0.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| simple_detect_secrets-0.0.4.tar.gz | 38.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| simple_detect_secrets-0.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 92.3 kB
Release files / simple_detect_secrets-0.0.4.tar.gz
| Download URL | simple_detect_secrets-0.0.4.tar.gz |
|---|---|
| Size | 38.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6b2ffb62ca3702d1d369fab3bdb99e3c6675536631ddae568954699e0c7dfe33
|
|
BLAKE2b-256 checksum How to use checksums |
0cd302632980ef5187e7f069e3bfc00c1aed89476a44b9421bf7d548154b6ea6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.8 {"installer":{"name":"uv","version":"0.10.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / simple_detect_secrets-0.0.4-py3-none-any.whl
| Download URL | simple_detect_secrets-0.0.4-py3-none-any.whl |
|---|---|
| Size | 53.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
86f314b57e90cd018a8d5ffc900388931b1bbe235401fb17fbf7efff2726e006
|
|
BLAKE2b-256 checksum How to use checksums |
4a55ce1078457a7c4065710296c539926b892735dad267366dc070a5f938a5a0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.8 {"installer":{"name":"uv","version":"0.10.8","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|