Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
detect-secrets — Un modo adatto alle aziende per rilevare e prevenire segreti nel codice. | Kitploit
Strumenti/GitHubGitHub/yelp/detect-secrets
Analisi StaticaAnalisi del CodiceDevSecOpsRilevamento SegretiTop in Rilevamento Segreti n.3
GitHubyelp/detect-secrets

detect-secrets

Un modo adatto alle aziende per rilevare e prevenire segreti nel codice.

Vedi Repository
4.6k564716 mesi faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Build Status PyPI version Homebrew PRs Welcome AMF

detect-secrets

Informazioni

detect-secrets è un modulo giustamente chiamato per (sorpresa, sorpresa) rilevare segreti all'interno di una base di codice.

Tuttavia, a differenza di altri pacchetti simili che si concentrano esclusivamente sulla ricerca di segreti, questo pacchetto è progettato pensando al cliente enterprise: fornendo un mezzo retrocompatibile e sistematico per:

  1. Prevenire l'ingresso di nuovi segreti nella base di codice,
  2. Rilevare se tali prevenzioni vengono esplicitamente ignorate, e
  3. Fornire una checklist di segreti da ruotare e migrare verso uno storage più sicuro.

In questo modo, si crea una separazione delle responsabilità: accettando che possano esserci attualmente segreti nascosti nel vostro grande repository (questo è ciò che chiamiamo una baseline), ma impedendo che il problema diventi più grande, senza dover affrontare lo sforzo potenzialmente enorme di spostare i segreti esistenti.

Lo fa eseguendo output diff periodici rispetto a espressioni regex costruite euristicamente, per identificare se è stato commesso un nuovo segreto. In questo modo, evita l'overhead di scavare in tutta la storia di git, così come la necessità di scansionare l'intero repository ogni volta.

Per dare un'occhiata ai cambiamenti recenti, consultare CHANGELOG.md.

Se desideri contribuire, consulta CONTRIBUTING.md.

Per documentazione più dettagliata, dai un'occhiata alla nostra altra documentazione.

Esempi

Avvio rapido:

Crea una baseline dei potenziali segreti attualmente trovati nel tuo repository git.```bash $ detect-secrets scan > .secrets.baseline

oppure, per eseguirlo da una directory diversa:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline

Scansione dei file non tracciati da git:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline

### Aggiunta di nuovi segreti alla baseline:

Questo eseguirà una nuova scansione del tuo codebase e:

1. Aggiorna/upgrade la tua baseline per renderla compatibile con l'ultima versione,
2. Aggiunge eventuali nuovi segreti trovati alla tua baseline,
3. Rimuove eventuali segreti non più presenti nel tuo codebase

Questo conserverà anche eventuali segreti etichettati che hai.```bash
$ detect-secrets scan --baseline .secrets.baseline

Per baseline più vecchie della versione 0.9, basta ricrearle.

Avvisi per segreti appena aggiunti:

Scansione solo dei file in staging:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

**Scansione di tutti i file tracciati:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

Visualizzare tutti i plugin abilitati:```bash

$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector

### Disabilitazione dei Plugin:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector

Se vuoi solo eseguire un plugin specifico, puoi fare:```bash $ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data

### Verifica di una Baseline:

Questo è un passaggio opzionale per etichettare i risultati nella tua baseline. Può essere utilizzato per restringere la tua checklist di segreti da migrare, o per configurare meglio i tuoi plugin al fine di migliorare il rapporto segnale-rumore.```bash
$ detect-secrets audit .secrets.baseline

Utilizzo in altri script Python

Uso base:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings

secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')

import json print(json.dumps(secrets.json(), indent=2))

**Configurazione più avanzata:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings

secrets = SecretsCollection()
with transient_settings({
    # Only run scans with only these plugins.
    # This format is the same as the one that is saved in the generated baseline.
    'plugins_used': [
        # Example of configuring a built-in plugin
        {
            'name': 'Base64HighEntropyString',
            'limit': 5.0,
        },

        # Example of using a custom plugin
        {
            'name': 'HippoDetector',
            'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
        },
    ],

    # We can also specify whichever additional filters we want.
    # This is an example of using the function `is_identified_by_ML_model` within the
    # local file `./private-filters/example.py`.
    'filters_used': [
        {
            'path': 'file://private-filters/example.py::is_identified_by_ML_model',
        },
    ]
}) as settings:
    # If we want to make any further adjustments to the created settings object (e.g.
    # disabling default filters), we can do so as such.
    settings.disable_filters(
        'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
        'detect_secrets.filters.heuristic.is_likely_id_string',
    )

    secrets.scan_file('test_data/config.ini')

Installazione```bash

$ pip install detect-secrets ✨🍰✨

Installa tramite [brew](https://brew.sh/):```bash
$ brew install detect-secrets

Utilizzo

detect-secrets viene fornito con tre diversi strumenti, e c'è spesso confusione su quale usare. Usa questa pratica checklist per aiutarti a decidere:

  1. Vuoi aggiungere segreti al tuo baseline? Se sì, usa detect-secrets scan.
  2. Vuoi ricevere avvisi per nuovi segreti non presenti nel baseline? Se sì, usa detect-secrets-hook.
  3. Stai analizzando il baseline stesso? Se sì, usa detect-secrets audit.
Scarica lo strumento