
Script Python pour analyser les dépôts Git à la recherche de chaînes intéressantes
Reposcanner est un script python qui parcourt l'historique des commits des dépôts Git à la recherche de chaînes intéressantes telles que des clés API, inspiré par truffleHog.
Le module python Git est requis (python3-git sur Debian).
docker build -t reposcanner .
docker run -it --rm reposcanner -h
docker run -it --rm reposcanner -r <repository>
./reposcanner -r <repository>
Options:
optional arguments:
-h, --help show this help message and exit
-r REPO, --repo REPO Repo to scan
-c COUNT, --count COUNT Number of commits to scan (default all)
-e ENTROPY, --entropy ENTROPY Minimum entropy to report (default 4.3)
-l LENGTH, --length LENGTH Maxmimum line length (default 500)
-b BRANCH, --branch BRANCH Scan a specific branch
-v, --verbose Verbose output
Exemple:
./reposcanner.py -r https://github.com/Dionach/reposcanner -v -a -c 30