
Una forma amigable para empresas de detectar y prevenir secretos en el código.
detect-secrets es un módulo con un nombre muy adecuado para (sorpresa, sorpresa) detectar secretos dentro de una base de código.
Sin embargo, a diferencia de otros paquetes similares que se centran únicamente en encontrar secretos, este paquete está diseñado pensando en el cliente empresarial: proporcionando una forma sistemática y compatible con versiones anteriores de:
De esta manera, se crea una separación de intereses: aceptando que puede haber actualmente secretos ocultos en su gran repositorio (a esto lo llamamos línea base), pero evitando que este problema crezca, sin tener que lidiar con el esfuerzo potencialmente gigantesco de eliminar los secretos existentes.
Lo hace ejecutando salidas de diff periódicas contra declaraciones regex heurísticamente diseñadas, para identificar si se ha comprometido algún secreto nuevo. De esta manera, evita la sobrecarga de excavar en todo el historial de git, así como la necesidad de escanear todo el repositorio cada vez.
Para ver los cambios recientes, consulte CHANGELOG.md.
Si desea contribuir, consulte CONTRIBUTING.md.
Para documentación más detallada, consulte nuestra otra documentación.
Cree una línea base de posibles secretos encontrados actualmente en su repositorio git.```bash $ detect-secrets scan > .secrets.baseline
o, para ejecutarlo desde un directorio diferente:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
Escaneo de archivos no rastreados por git:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### Agregar nuevos secretos a la línea base:
Esto volverá a escanear tu base de código, y:
1. Actualizar/mejorar tu línea base para que sea compatible con la última versión,
2. Agregar cualquier nuevo secreto que encuentre a tu línea base,
3. Eliminar cualquier secreto que ya no esté en tu base de código
Esto también preservará cualquier secreto etiquetado que tengas.```bash
$ detect-secrets scan --baseline .secrets.baseline
Para líneas base anteriores a la versión 0.9, simplemente vuelva a crearla.
Escaneando solo archivos staged:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**Escaneando Todos los Archivos Rastreados:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### Desactivando Plugins:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
Si quieres ejecutar solo un plugin específico, puedes hacer:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### Auditoría de una Línea Base:
Este es un paso opcional para etiquetar los resultados en tu línea base. Se puede usar para reducir tu
lista de secretos a migrar, o para configurar mejor tus complementos y mejorar su relación señal-ruido.```bash
$ detect-secrets audit .secrets.baseline
Uso básico:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**Configuración más avanzada:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
Instalar mediante [brew](https://brew.sh/):```bash
$ brew install detect-secrets
detect-secrets viene con tres herramientas diferentes, y a menudo hay confusión sobre cuál usar. Utilice esta práctica lista de verificación para ayudarle a decidir:
detect-secrets scan.detect-secrets-hook.detect-secrets audit.