
Sicheres CLI-Tool zur Verwaltung von Umgebungsgeheimnissen unter Verwendung nativer Betriebssystem-Anmeldeinformationsspeicher (macOS Keychain, Linux Secret Service, Windows Credential Manager)
Sichere Verwaltung von Umgebungsgeheimnissen mit nativen OS-Anmeldedatenspeichern.

myapp.dev, stripe-api.prod, work.staging)cmd (suchen, auflisten, ausführen, löschen).env-Dateien (mit Generierungsverfolgung über audit)eval $(envsec env)).env-Dateien (mit Konflikterkennung)envsec tui) zur Verwaltung von Geheimnissen ohne Befehle auswendig zu lernenDies ist ein Monorepo, das die folgenden Pakete enthält:
| Paket | Beschreibung | npm |
|---|---|---|
envsec | CLI-Tool zur Verwaltung von Geheimnissen | |
@envsec/sdk | Node.js / Bun SDK zum programmatischen Laden von Geheimnissen | |
@envsec/core | Kern-Engine — OS-Anmeldedatenspeicher-Adapter + Metadaten-DB | |
@envsec/tui | Interaktive Terminal-Benutzeroberfläche für die Verwaltung von Geheimnissen |
Für den programmatischen Zugriff auf Geheimnisse aus Node.js oder Bun verwenden Sie @envsec/sdk:```bash
npm install @envsec/sdk
# Installation
## From source
Before you start, make sure you have the following requirements:
- Go 1.22 or higher
- Make
```bash
git clone https://github.com/projectdiscovery/katana.git
cd katana
go build
./katana -h
go install github.com/projectdiscovery/katana/cmd/katana@latest
docker pull projectdiscovery/katana
katana -h
This will display help for the tool. Here are all the switches it supports.
katana is a fast crawler focused on automation in the field of security testing.
Usage:
katana [flags]
Flags:
INPUT:
-u, -list string[] target url / list to crawl
-r, -resume string resume scan using resume.cfg
-e, -exclude string exclude host matching specified filter ('cdn', 'private-ips', cidr, ip, port, host, protocol, extension, path, query, length, depth, regex)
CONFIGURATION:
-d, -depth int maximum depth to crawl (default 3)
-jc, -js-crawl enable endpoint parsing / crawling in javascript file
-jsl, -js-limit int limit the number of javascript files to parse (default 100)
-m, -strategy string crawl strategy. depth-first (dfs) or breadth-first (bfs) (default "bfs")
-X, -method string request method (GET, POST, HEAD, OPTIONS, PUT, PATCH, DELETE, CONNECT, TRACE, CUSTOM) (default "GET")
-H, -headers string[] custom header/cookie to include in all http request in header:value format (file)
-ct, -crawl-duration value maximum duration to crawl the target for (s, m, h, d) (default 0)
-ef, -extension-filter string[] filter to only crawl specified extensions
-em, -extension-match string[] match specified extensions
-iq, -ignore-query ignore query strings in URLs
-irr, -ignore-regex string ignore URLs matching this regex
-kf, -known-files string enable crawling of known files (all, robotstxt, sitemapxml)
-mrs, -max-response-size int maximum response size to read (default 9223372036854775807)
-timeout int time to wait for request in seconds (default 10)
-aff, -automatic-form-fill enable automatic form filling
-fx, -form-extraction extract form, input, textarea & select elements in jsonl output
-retry int number of times to retry the request (default 1)
-proxy string[] http/socks5 proxy to use (list of proxies)
-Hl, -header-line use header:value format for headers
-config string path to the katana configuration file
-fc, -form-config string path to a custom form configuration file
-fl, -field strings field to fill in form (name, value)
-cs, -crawl-scope string[] in scope url regex to be followed by crawler
-do, -crawl-out-scope crawl out of scope URLs
-nc, -no-color disable colors in output
-silent display output only
-v, -verbose display verbose output
-version display project version
-hc, -health-check run health check
-elog, -error-log string file to write sent requests error log
FILTER:
-mr, -match-regex string[] regex or list of regex to match on output url (cli, file)
-fr, -filter-regex string[] regex or list of regex to filter on output url (cli, file)
-fq, -filter-qr string[] filter url with query parameters matching regex
-sf, -scope-filter string[] filter scope urls with regex
-s, -strategy string crawl strategy. depth-first (dfs) or breadth-first (bfs) (default "bfs")
-f, -field string field to display in output (url,path,fqdn,rdn,rurl,qurl,file,key,value,kv,dir,udir)
-sf, -store-field string field to store in per-host input (url,path,fqdn,rdn,rurl,qurl,file,key,value,kv,dir,udir)
-tl, -tls enable tls based routing
-tlsi, -tls-impersonate enable experimental client hello impersonation
RATE-LIMIT:
-c, -concurrency int number of concurrent fetchers to use (default 10)
-p, -parallelism int number of concurrent requests per host (default 10)
-rd, -delay int request delay between each request in seconds
-rl, -rate-limit int maximum requests to send per second (default 150)
-rlm, -rate-limit-minute int maximum number of requests to send per minute
UPDATE:
-up, -update update katana to latest version
-duc, -disable-update-check disable automatic katana update check