
detect-secrets は、コードベース内のシークレットを検出するための、適切に名付けられた(予想通り)モジュールです。
しかし、シークレットの発見のみに焦点を当てている他の同様のパッケージとは異なり、このパッケージはエンタープライズクライアントを念頭に置いて設計されています。後方互換性のある体系的な方法を提供します:
このようにして、関心の分離を実現します。大規模なリポジトリに現在シークレットが隠れている可能性があることを認め(これを_ベースライン_と呼びます)、しかし、この問題がさらに拡大するのを防ぎつつ、既存のシークレットを移動するという潜在的に膨大な作業に対処することはありません。
これは、ヒューリスティックに作成された正規表現に対して定期的な差分出力を実行することで、新しいシークレットがコミットされたかどうかを識別します。これにより、すべてのgit履歴を掘り起こすオーバーヘッドを回避し、毎回リポジトリ全体をスキャンする必要もなくなります。
最近の変更については、CHANGELOG.md をご覧ください。
コントリビューションを検討されている場合は、CONTRIBUTING.md をご覧ください。
より詳細なドキュメントについては、他のドキュメントをご確認ください。
現在Gitリポジトリで見つかった潜在的なシークレットのベースラインを作成します。```bash $ detect-secrets scan > .secrets.baseline
または、別のディレクトリから実行する場合:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
Git追跡対象外のファイルをスキャン:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### ベースラインへの新しいシークレットの追加:
これにより、コードベースが再スキャンされ、以下の処理が行われます:
1. 最新バージョンと互換性を持つようにベースラインを更新/アップグレードします。
2. 見つかった新しいシークレットをベースラインに追加します。
3. コードベースに存在しなくなったシークレットを削除します。
これにより、ラベル付けされたシークレットも保持されます。```bash
$ detect-secrets scan --baseline .secrets.baseline
バージョン0.9より古いベースラインの場合は、単に再作成してください。
ステージングされたファイルのみをスキャン:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**すべての追跡ファイルをスキャン中:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### プラグインの無効化:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
特定のプラグインのみを実行したい場合は、次のようにします:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### ベースラインの監査:
これは、ベースラインの結果にラベルを付けるためのオプションのステップです。これを使用して、移行するシークレットのチェックリストを絞り込んだり、プラグインをより適切に設定してシグナル対ノイズ比を向上させたりすることができます。```bash
$ detect-secrets audit .secrets.baseline
基本的な使い方:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**より高度な設定:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
[brew](https://brew.sh/)経由でインストール:```bash
$ brew install detect-secrets
detect-secrets には3つの異なるツールが用意されており、どれを使うべきか迷うことがよくあります。以下の便利なチェックリストを参考に、適切なツールを選んでください。
detect-secrets scan を使用します。detect-secrets-hook を使用します。detect-secrets audit を使用します。$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]
Scans a repository for secrets in code. The generated output is compatible
with detect-secrets-hook --baseline.
positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.
optional arguments:
-h, --help show this help message and exit
--string [STRING] Scans an individual string, and displays configured
plugins' verdict.
--only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions
are indeed non-secrets.