Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
detect-secrets — コード内のシークレットを検出・防止するためのエンタープライズ向けの方法。 | Kitploit
ツール/GitHubGitHub/yelp/detect-secrets
静的分析コード分析DevSecOpsシークレット検出シークレット検出 第3位
GitHubyelp/detect-secrets

detect-secrets

コード内のシークレットを検出・防止するためのエンタープライズ向けの方法。

リポジトリを見る
4.6k564716ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Build Status PyPI version Homebrew PRs Welcome AMF

detect-secrets

概要

detect-secrets は、コードベース内のシークレットを検出するための、適切に名付けられた(予想通り)モジュールです。

しかし、シークレットの発見のみに焦点を当てている他の同様のパッケージとは異なり、このパッケージはエンタープライズクライアントを念頭に置いて設計されています。後方互換性のある体系的な方法を提供します:

  1. 新しいシークレットがコードベースに入るのを防ぐ
  2. そのような防止策が明示的にバイパスされたかどうかを検出する
  3. ローテーションするシークレットのチェックリストを提供し、より安全なストレージに移行する

このようにして、関心の分離を実現します。大規模なリポジトリに現在シークレットが隠れている可能性があることを認め(これを_ベースライン_と呼びます)、しかし、この問題がさらに拡大するのを防ぎつつ、既存のシークレットを移動するという潜在的に膨大な作業に対処することはありません。

これは、ヒューリスティックに作成された正規表現に対して定期的な差分出力を実行することで、新しいシークレットがコミットされたかどうかを識別します。これにより、すべてのgit履歴を掘り起こすオーバーヘッドを回避し、毎回リポジトリ全体をスキャンする必要もなくなります。

最近の変更については、CHANGELOG.md をご覧ください。

コントリビューションを検討されている場合は、CONTRIBUTING.md をご覧ください。

より詳細なドキュメントについては、他のドキュメントをご確認ください。

例

クイックスタート:

現在Gitリポジトリで見つかった潜在的なシークレットのベースラインを作成します。```bash $ detect-secrets scan > .secrets.baseline

または、別のディレクトリから実行する場合:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline

Git追跡対象外のファイルをスキャン:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline

### ベースラインへの新しいシークレットの追加:

これにより、コードベースが再スキャンされ、以下の処理が行われます:

1. 最新バージョンと互換性を持つようにベースラインを更新/アップグレードします。
2. 見つかった新しいシークレットをベースラインに追加します。
3. コードベースに存在しなくなったシークレットを削除します。

これにより、ラベル付けされたシークレットも保持されます。```bash
$ detect-secrets scan --baseline .secrets.baseline

バージョン0.9より古いベースラインの場合は、単に再作成してください。

新たに追加されたシークレットのアラートをオフにする:

ステージングされたファイルのみをスキャン:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

**すべての追跡ファイルをスキャン中:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

すべての有効なプラグインの表示:```bash

$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector

### プラグインの無効化:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector

特定のプラグインのみを実行したい場合は、次のようにします:```bash $ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data

### ベースラインの監査:

これは、ベースラインの結果にラベルを付けるためのオプションのステップです。これを使用して、移行するシークレットのチェックリストを絞り込んだり、プラグインをより適切に設定してシグナル対ノイズ比を向上させたりすることができます。```bash
$ detect-secrets audit .secrets.baseline

他のPythonスクリプトでの使用法

基本的な使い方:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings

secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')

import json print(json.dumps(secrets.json(), indent=2))

**より高度な設定:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings

secrets = SecretsCollection()
with transient_settings({
    # Only run scans with only these plugins.
    # This format is the same as the one that is saved in the generated baseline.
    'plugins_used': [
        # Example of configuring a built-in plugin
        {
            'name': 'Base64HighEntropyString',
            'limit': 5.0,
        },

        # Example of using a custom plugin
        {
            'name': 'HippoDetector',
            'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
        },
    ],

    # We can also specify whichever additional filters we want.
    # This is an example of using the function `is_identified_by_ML_model` within the
    # local file `./private-filters/example.py`.
    'filters_used': [
        {
            'path': 'file://private-filters/example.py::is_identified_by_ML_model',
        },
    ]
}) as settings:
    # If we want to make any further adjustments to the created settings object (e.g.
    # disabling default filters), we can do so as such.
    settings.disable_filters(
        'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
        'detect_secrets.filters.heuristic.is_likely_id_string',
    )

    secrets.scan_file('test_data/config.ini')

インストール```bash

$ pip install detect-secrets ✨🍰✨

[brew](https://brew.sh/)経由でインストール:```bash
$ brew install detect-secrets

使い方

detect-secrets には3つの異なるツールが用意されており、どれを使うべきか迷うことがよくあります。以下の便利なチェックリストを参考に、適切なツールを選んでください。

  1. ベースラインにシークレットを追加したい場合: detect-secrets scan を使用します。
  2. ベースラインにない新しいシークレットを警告したい場合: detect-secrets-hook を使用します。
  3. ベースライン自体を分析したい場合: detect-secrets audit を使用します。

ベースラインへのシークレットの追加```

$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]

Scans a repository for secrets in code. The generated output is compatible with detect-secrets-hook --baseline.

positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.

optional arguments: -h, --help show this help message and exit --string [STRING] Scans an individual string, and displays configured plugins' verdict. --only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions are indeed non-secrets.

ツールをダウンロード