
deepsecrets
Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

An enterprise friendly way of detecting and preventing secrets in code.

Pluggable linting tool to prevent committing credential.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

safely install npm packages by auditing them pre-install stage

Performing security tests inside your CI

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…


Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

Detects and auto-fixes hardcoded secrets in Python repos — refuses when the fix could break your code

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

Checks projects for compromised packages, suspicious files, and import statements.


Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574