detect-secrets
Yelp
Python secret scanner built around a baseline file, so teams can block new credentials from entering a repository without first cleaning up every historical finding.
Secret Scanning
Find credentials, tokens and keys committed to code or exposed in build systems.
9 tools profiled
How it differs Finds credentials committed to code, git history and build artifacts. Vulnerable dependencies are SCA, not this.
Yelp
Python secret scanner built around a baseline file, so teams can block new credentials from entering a repository without first cleaning up every historical finding.
AWS Labs
Shell-based git hook that refuses commits matching a configured set of credential patterns, with built-in rules for AWS access keys.
GitGuardian
Platform that scans internal repositories and public code for leaked credentials and tracks each finding as an incident through validation, ownership and rotation.
GitHub
GitHub's built-in scanner that matches partner-registered credential patterns on push, can block the push outright, and notifies issuing providers so they can revoke.
Gitleaks
Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.
Yelp
Python secret scanner built around a baseline file, so teams can block new credentials from entering a repository without first cleaning up every historical finding.
AWS Labs
Shell-based git hook that refuses commits matching a configured set of credential patterns, with built-in rules for AWS access keys.
GitGuardian
Platform that scans internal repositories and public code for leaked credentials and tracks each finding as an incident through validation, ownership and rotation.
GitHub
GitHub's built-in scanner that matches partner-registered credential patterns on push, can block the push outright, and notifies issuing providers so they can revoke.
Gitleaks
Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.
MongoDB
Rust secret scanner that pairs a high-throughput regular expression engine with language-aware parsing and live validation of the credentials it finds.
Check Point
Commercial scanner that looks for hardcoded credentials and configuration exposure across source, infrastructure code and build output, with a developer-facing CLI and a central console.
Thoughtworks
Git hook from Thoughtworks that inspects outgoing changes for credential-shaped content, risky filenames and high entropy strings, and refuses the commit or push.
Truffle Security
Secret scanner that calls each provider's API to confirm whether a discovered credential is active, across git history, cloud storage, container images and chat and ticketing systems.
MongoDB
Rust secret scanner that pairs a high-throughput regular expression engine with language-aware parsing and live validation of the credentials it finds.
Check Point
Commercial scanner that looks for hardcoded credentials and configuration exposure across source, infrastructure code and build output, with a developer-facing CLI and a central console.
Thoughtworks
Git hook from Thoughtworks that inspects outgoing changes for credential-shaped content, risky filenames and high entropy strings, and refuses the commit or push.
Truffle Security
Secret scanner that calls each provider's API to confirm whether a discovered credential is active, across git history, cloud storage, container images and chat and ticketing systems.