
secretlint v13.0.4
プラグイン可能なリンターツールで、認証情報のコミットを防止します。
Secretlint 

Secretlint は、認証情報のコミットを防ぐためのプラグイン可能なリンティングツールです。
機能
- スキャナー: プロジェクト内の認証情報を検出して報告します
- プロジェクト フレンドリー: プロジェクトへのセットアップや CI サービスとの統合が簡単です
- Pre-Commit フック: 認証情報ファイルのコミットを防ぎます
- プラグイン可能: カスタムルールの作成と柔軟な設定が可能です
- ドキュメント: そのルールがなぜシークレットとして検出したかの理由を説明します
クイックデモ
secretlint のリンティング結果は https://secretlint.github.io/ で確認できます。
クイックスタート
1 つのコマンドで、あなたのプロジェクトで Secretlint を試すことができます。
すでに Docker をインストールしている場合:
docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"
すでに Node.js をインストールしている場合:
npx @secretlint/quick-start "**/*"
実行後、
空の結果が得られ、終了ステータスが 0 であれば、あなたのプロジェクトは安全です。
そうでなければ、何らかのエラーレポートが得られ、あなたのプロジェクトには生データとして認証情報が含まれています。

継続的なセキュリティを実現したい場合は、以下のインストールガイドを参照し、pre-commit フックと CI をセットアップしてください。
インストール
Docker を使用する
前提条件: Docker が必要です
私たちの Docker コンテナを使用すると、Node.js と secretlint が動作する環境を、ダウンロードできる限り速く入手できます。
以下のコマンドで、カレントディレクトリ配下のすべてのファイルを secretlint でチェックできます:
docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"
secretlint/secretlint Docker コンテナは、設計上、設定なしで動作します。
この Docker イメージには以下のパッケージが組み込まれています:
- @secretlint/secretlint-rule-preset-recommend
- @secretlint/secretlint-rule-pattern
- @secretlint/secretlint-formatter-sarif
詳細については、secretlint の Dockerfile を参照してください。
Node.js を使用する
前提条件: Node.js 22+ が必要です。
Secretlint は JavaScript で書かれています。 Secretlint は npm を使用してインストールできます:``` npm install secretlint @secretlint/secretlint-rule-preset-recommend --save-dev
その後、設定ファイルを作成する必要があります:```
npx secretlint --init
最後に、Secretlint は次のように任意のファイルまたはディレクトリに対して実行できます:``` npx secretlint "**/*"
:memo: Secretlintは[globパターン](https://github.com/mrmlnc/fast-glob#basic-syntax)をサポートしており、globパターンは二重引用符で囲む必要があります。
`npm install --global`を使用してSecretlintをグローバルにインストールすることも可能です。ただし、推奨しません。一部のルールがグローバルで壊れる可能性があります。
### 単一実行可能バイナリの使用
**前提条件:** なし
単一実行可能バイナリを使用することで、Node.jsなしで`secretlint`コマンドを使用できます。
1. [Releasesページ](https://github.com/secretlint/secretlint/releases)から最新のバイナリをダウンロードします
2. ファイルのパーミッションを実行可能に変更します: `chmod +x ./secretlint`
3. `./secretlint --init`を実行して設定ファイルを作成します
4. `./secretlint "**/*"`を実行してプロジェクトをリントします
詳細については、[publish/binary-compiler](https://github.com/secretlint/secretlint/blob/master/publish/binary-compiler) READMEを参照してください。
## 使用方法
`secretlint --help`で使用方法が表示されます。
Secretlint CLI that scan secret/credential data.
Usage
$ secretlint [file|glob*]
Note
supported glob syntax is based on picomatch (the engine used by micromatch)
https://github.com/micromatch/picomatch#globbing-features
https://github.com/micromatch/micromatch#matching-features
Options
--init setup config file. Create .secretlintrc.json file from your package.json
--format [String] formatter name. Default: "stylish". Available Formatter: checkstyle, compact, github, jslint-xml, junit, pretty-error, stylish, tap, unix, json, mask-result, table
--output [path:String] output file path that is written of reported result.
--secretlintrc [path:String] path to .secretlintrc config file. Default: .secretlintrc.*
--secretlintignore [path:String] path to .secretlintignore file. Default: .secretlintignore
--stdinFileName [String] filename to process STDIN content. Some rules depend on filename to check content.
--no-color disable ANSI-color of output.
--no-terminalLink disable terminalLink of output.
--no-maskSecrets disable masking of secret values; secrets are masked by default.
--no-glob disable glob pattern interpretation; treat all inputs as literal file paths.
--no-gitignore disable .gitignore cascade respect; .gitignore files are
respected by default (since v13).
Options for Developer
--profile Enable performance profile.
--secretlintrcJSON [String] a JSON string of .secretlintrc. use JSON string instead of rc file.
Experimental Options
--locale [String] locale tag for translating message. Default: en
Examples
# Scan a single file
$ secretlint ./README.md
# Scan all files (wrap glob in double quotes to avoid shell expansion)
$ secretlint "**/*"
$ secretlint "source/**/*.ini"
# Treat inputs as literal paths (for SvelteKit (group) / Next.js [param] etc.)
$ secretlint --no-glob "src/(auth)/login.ts"
# Lint STDIN content (filename hint affects which rules apply)
$ echo "SECRET" | secretlint --stdinFileName=secret.txt
# Use a custom config file
$ secretlint "**/*" --secretlintrc=.secretlintrc.custom.json
# Scan files ignored by .gitignore (e.g. to verify build artifacts)
$ secretlint --no-gitignore "dist/**/*"
# Mask secrets in a file in-place
$ secretlint .zsh_history --format=mask-result --output=.zsh_history
# Output JSON for programmatic parsing
$ secretlint "**/*" --format=json --output=secretlint-report.json
# Output GitHub Actions annotations in CI
$ secretlint "**/*" --format=github
Exit Status
Secretlint exits with the following values:
- 0:
- Linting succeeded, no errors found.
- Found lint error but --output is specified.
- 1:
- Linting failed, errors found.
- 2:
- Unexpected error occurred, fatal error.
## 設定
Secretlintには設定ファイル`.secretlintrc.{json,yml,js}`があります。
- ドキュメント: [Configuring Secretlint](https://github.com/secretlint/secretlint/blob/master/docs/configuration.md)
`secretlint --init`を実行すると、ディレクトリに`.secretlintrc.json`ファイルが作成されます。
その中には、次のようにいくつかのルールが設定されているのがわかります:```json
{
"rules": [
{
"id": "@secretlint/secretlint-rule-preset-recommend"
}
]
}
id プロパティは secretlint ルールパッケージの名前です。
Secretlint には組み込みのルールがありません。
ルールを追加したい場合は、パッケージを インストール し、そのルールを .secretlintrc ファイルに 追加 する必要があります。
各ルールは同じ設定パターンを持っています:
options: ルールのオプション定義。詳細は各ルールのドキュメントを参照してくださいdisabled:disabledがtrueの場合、そのルールを無効にしますallowMessageIds:allowMessageIdsはエラー報告を抑制したいメッセージ ID の配列です- メッセージ ID は各ルールで定義されています。ルールのドキュメントを参照してください
例: options
例えば、@secretlint/secretlint-rule-example には options に allows があります。
この allows オプションは、無視したい RegExp-like String のリストを定義します。```json
{
"rules": [
{
"id": "@secretlint/secretlint-rule-example",
"options": {
"allows": [
"/dummy_secret/i"
]
}
}
]
}
`@secretlint/secretlint-rule-preset-recommend` のようなプリセットを使用する場合、オプションは `rules` に記述する必要があります。