
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

An enterprise friendly way of detecting and preventing secrets in code.

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Cloud native secrets management for developers - never leave your command line for secrets.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Performing security tests inside your CI

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Project Aura: Security auditing and code introspection

Open-source secret scanner in Rust

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…


Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…