
एंटरप्राइज़ के अनुकूल तरीके से कोड में गुप्त जानकारी का पता लगाना और उसे रोकना।
detect-secrets एक उपयुक्त नाम वाला मॉड्यूल है जो (आश्चर्य, आश्चर्य) रहस्यों का पता लगाने के लिए है
एक कोड बेस के भीतर।
हालाँकि, अन्य समान पैकेजों के विपरीत जो केवल रहस्यों को खोजने पर ध्यान केंद्रित करते हैं, यह पैकेज एंटरप्राइज़ क्लाइंट को ध्यान में रखकर डिज़ाइन किया गया है: एक पिछड़ा संगत, व्यवस्थित साधन प्रदान करता है:
इस तरह, आप एक चिंता का पृथक्करण बनाते हैं: यह स्वीकार करना कि आपके बड़े रिपॉजिटरी में वर्तमान में रहस्य छिपे हो सकते हैं (इसे हम बेसलाइन कहते हैं), लेकिन इस समस्या को और बढ़ने से रोकना, मौजूदा रहस्यों को हटाने के संभावित विशाल प्रयास से निपटने के बिना।
यह अनुमानित रूप से तैयार किए गए रेगेक्स स्टेटमेंट के विरुद्ध आवधिक डिफ आउटपुट चलाकर ऐसा करता है, यह पहचानने के लिए कि क्या कोई नया रहस्य प्रतिबद्ध किया गया है। इस तरह, यह सभी गिट हिस्ट्री खंगालने के ओवरहेड से बचता है, साथ ही हर बार पूरे रिपॉजिटरी को स्कैन करने की आवश्यकता से भी बचता है।
हाल के बदलावों को देखने के लिए, कृपया देखें CHANGELOG.md।
यदि आप योगदान देना चाहते हैं, तो कृपया देखें CONTRIBUTING.md।
अधिक विस्तृत दस्तावेज़ीकरण के लिए, हमारे अन्य दस्तावेज़ देखें।
अपने गिट रिपॉजिटरी में वर्तमान में पाए गए संभावित रहस्यों का एक बेसलाइन बनाएँ।```bash $ detect-secrets scan > .secrets.baseline
या, किसी भिन्न निर्देशिका से चलाने के लिए:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
गैर-गिट ट्रैक की गई फ़ाइलों को स्कैन करना:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### बेसलाइन में नए रहस्य जोड़ना:
यह आपके कोडबेस को पुनः स्कैन करेगा, और:
1. नवीनतम संस्करण के साथ संगत होने के लिए आपकी बेसलाइन को अपडेट/अपग्रेड करेगा,
2. आपकी बेसलाइन में मिलने वाले किसी भी नए रहस्य को जोड़ेगा,
3. आपके कोडबेस से अब हटाए गए किसी भी रहस्य को हटाएगा
यह आपके द्वारा लेबल किए गए किसी भी रहस्य को भी संरक्षित करेगा।```bash
$ detect-secrets scan --baseline .secrets.baseline
संस्करण 0.9 से पुराने बेसलाइन्स के लिए, बस इसे पुनः बनाएं।
केवल स्टेज की गई फ़ाइलों को स्कैन करना:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**सभी ट्रैक की गई फ़ाइलों को स्कैन करना:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### प्लगइन्स को अक्षम करना:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
यदि आप केवल एक विशिष्ट प्लगइन चलाना चाहते हैं, तो आप ऐसा कर सकते हैं:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### आधार रेखा का ऑडिट करना:
यह आपकी आधार रेखा में परिणामों को लेबल करने का एक वैकल्पिक कदम है। इसका उपयोग माइग्रेट करने के लिए रहस्यों की अपनी चेकलिस्ट को संकीर्ण करने,
या अपने प्लगइन्स को बेहतर ढंग से कॉन्फ़िगर करने के लिए किया जा सकता है ताकि इसका सिग्नल-टू-शोर
अनुपात बेहतर हो सके।```bash
$ detect-secrets audit .secrets.baseline
मूल उपयोग:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**अधिक उन्नत कॉन्फ़िगरेशन:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
[brew](https://brew.sh/) के माध्यम से इंस्टॉल करें:```bash
$ brew install detect-secrets
detect-secrets तीन अलग-अलग उपकरणों के साथ आता है, और अक्सर इस बात को लेकर भ्रम होता है कि किसका उपयोग करना चाहिए। आपकी सहायता के लिए यह सुविधाजनक चेकलिस्ट का उपयोग करें:
detect-secrets scan का उपयोग करें।detect-secrets-hook का उपयोग करें।detect-secrets audit का उपयोग करें।