
secretlint v13.0.4
크리덴셜 커밋을 방지하는 플러그형 린팅 도구.
Secretlint 

Secretlint은 자격 증명 커밋을 방지하기 위한 플러그인 방식의 린팅 도구입니다.
기능
- 스캐너: 프로젝트에서 자격 증명을 찾아 보고합니다
- 프로젝트 친화적: 프로젝트 설정과 CI 서비스 통합이 쉽습니다
- Pre-Commit Hook: 자격 증명 파일 커밋을 방지합니다
- 플러그인 방식: 사용자 정의 규칙 생성과 유연한 구성을 지원합니다
- 문서화: 해당 규칙이 왜 비밀로 감지했는지에 대한 이유를 설명합니다
빠른 데모
https://secretlint.github.io/에서 secretlint 린팅 결과를 확인할 수 있습니다.
빠른 시작
한 번의 명령으로 프로젝트에서 Secretlint를 사용해 볼 수 있습니다.
Docker가 이미 설치되어 있다면:
docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"
Node.js가 이미 설치되어 있다면:
npx @secretlint/quick-start "**/*"
실행 후,
빈 결과가 나오고 종료 상태가 0이라면 프로젝트는 안전합니다.
그렇지 않고 오류 보고가 나온다면 프로젝트에 자격 증명이 원시 데이터로 포함되어 있는 것입니다.

지속적인 보안을 원한다면 다음 설치 가이드를 참고하여 pre-commit hook과 CI를 설정하세요.
설치
Docker 사용
사전 요구 사항: Docker 필요
Node.js와 secretlint가 실행되는 환경을 최대한 빠르게 다운로드할 수 있도록 Docker 컨테이너를 사용하세요.
다음 명령으로 현재 디렉터리의 모든 파일을 secretlint로 검사할 수 있습니다:
docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"
secretlint/secretlint docker 컨테이너는 설계상 구성 없이 작동합니다.
이 Docker 이미지에는 다음 패키지가 내장되어 있습니다:
- @secretlint/secretlint-rule-preset-recommend
- @secretlint/secretlint-rule-pattern
- @secretlint/secretlint-formatter-sarif
자세한 내용은 secretlint의 Dockerfile을 참고하세요.
Node.js 사용
사전 요구 사항: Node.js 22+ 필요.
Secretlint는 JavaScript로 작성되었습니다. npm을 사용하여 Secretlint를 설치할 수 있습니다:``` npm install secretlint @secretlint/secretlint-rule-preset-recommend --save-dev
그런 다음 구성 파일을 설정해야 합니다:```
npx secretlint --init
마지막으로, 다음과 같이 모든 파일이나 디렉터리에서 Secretlint를 실행할 수 있습니다:``` npx secretlint "**/*"
:memo: Secretlint는 [glob 패턴](https://github.com/mrmlnc/fast-glob#basic-syntax)을 지원하며, glob 패턴은 큰따옴표로 감싸야 합니다.
`npm install --global`을 사용하여 Secretlint를 전역으로 설치하는 것도 가능합니다. 하지만 권장하지 않으며, 일부 규칙이 전역에서 깨질 수 있습니다.
### 단일 실행 파일 바이너리 사용
**사전 요구 사항:** 없음
단일 실행 파일 바이너리를 사용하면 Node.js 없이 `secretlint` 명령을 사용할 수 있습니다.
1. [Releases 페이지](https://github.com/secretlint/secretlint/releases)에서 최신 바이너리를 다운로드합니다.
2. 파일 권한을 실행 가능으로 변경합니다: `chmod +x ./secretlint`
3. `./secretlint --init`을 실행하여 구성 파일을 생성합니다.
4. `./secretlint "**/*"`를 실행하여 프로젝트를 린트합니다.
자세한 내용은 [publish/binary-compiler](https://github.com/secretlint/secretlint/blob/master/publish/binary-compiler) README를 참조하세요.
## 사용법
`secretlint --help`는 사용법을 표시합니다.
Secretlint CLI that scan secret/credential data.
Usage
$ secretlint [file|glob*]
Note
supported glob syntax is based on picomatch (the engine used by micromatch)
https://github.com/micromatch/picomatch#globbing-features
https://github.com/micromatch/micromatch#matching-features
Options
--init setup config file. Create .secretlintrc.json file from your package.json
--format [String] formatter name. Default: "stylish". Available Formatter: checkstyle, compact, github, jslint-xml, junit, pretty-error, stylish, tap, unix, json, mask-result, table
--output [path:String] output file path that is written of reported result.
--secretlintrc [path:String] path to .secretlintrc config file. Default: .secretlintrc.*
--secretlintignore [path:String] path to .secretlintignore file. Default: .secretlintignore
--stdinFileName [String] filename to process STDIN content. Some rules depend on filename to check content.
--no-color disable ANSI-color of output.
--no-terminalLink disable terminalLink of output.
--no-maskSecrets disable masking of secret values; secrets are masked by default.
--no-glob disable glob pattern interpretation; treat all inputs as literal file paths.
--no-gitignore disable .gitignore cascade respect; .gitignore files are
respected by default (since v13).
Options for Developer
--profile Enable performance profile.
--secretlintrcJSON [String] a JSON string of .secretlintrc. use JSON string instead of rc file.
Experimental Options
--locale [String] locale tag for translating message. Default: en
Examples
# Scan a single file
$ secretlint ./README.md
# Scan all files (wrap glob in double quotes to avoid shell expansion)
$ secretlint "**/*"
$ secretlint "source/**/*.ini"
# Treat inputs as literal paths (for SvelteKit (group) / Next.js [param] etc.)
$ secretlint --no-glob "src/(auth)/login.ts"
# Lint STDIN content (filename hint affects which rules apply)
$ echo "SECRET" | secretlint --stdinFileName=secret.txt
# Use a custom config file
$ secretlint "**/*" --secretlintrc=.secretlintrc.custom.json
# Scan files ignored by .gitignore (e.g. to verify build artifacts)
$ secretlint --no-gitignore "dist/**/*"
# Mask secrets in a file in-place
$ secretlint .zsh_history --format=mask-result --output=.zsh_history
# Output JSON for programmatic parsing
$ secretlint "**/*" --format=json --output=secretlint-report.json
# Output GitHub Actions annotations in CI
$ secretlint "**/*" --format=github
Exit Status
Secretlint exits with the following values:
- 0:
- Linting succeeded, no errors found.
- Found lint error but --output is specified.
- 1:
- Linting failed, errors found.
- 2:
- Unexpected error occurred, fatal error.
## 구성
Secretlint에는 구성 파일 `.secretlintrc.{json,yml,js}`가 있습니다.
- 문서: [Configuring Secretlint](https://github.com/secretlint/secretlint/blob/master/docs/configuration.md)
`secretlint --init`을 실행한 후, 디렉터리에 `.secretlintrc.json` 파일이 생성됩니다.
그 안에서 다음과 같이 구성된 몇 가지 규칙을 볼 수 있습니다:```json
{
"rules": [
{
"id": "@secretlint/secretlint-rule-preset-recommend"
}
]
}
id 속성은 secretlint 규칙 패키지의 이름입니다.
Secretlint에는 내장 규칙이 없습니다.
규칙을 추가하려면 패키지를 설치하고 .secretlintrc 파일에 규칙을 추가해야 합니다.
각 규칙은 동일한 구성 패턴을 가집니다:
options: 규칙에 대한 옵션 정의입니다. 자세한 내용은 각 규칙 문서를 참조하세요disabled:disabled가true이면 규칙을 비활성화합니다allowMessageIds:allowMessageIds는 오류 보고를 억제하려는 메시지 id의 배열입니다- 메시지 id는 각 규칙에 정의되어 있으며 규칙 문서를 참조하세요
예시: options
예를 들어, @secretlint/secretlint-rule-example은 options에 allows를 가집니다.
이 allows 옵션은 무시하려는 RegExp-like String 목록을 정의합니다.```json
{
"rules": [
{
"id": "@secretlint/secretlint-rule-example",
"options": {
"allows": [
"/dummy_secret/i"
]
}
}
]
}
`@secretlint/secretlint-rule-preset-recommend`와 같은 preset을 사용할 때는 옵션을 `rules`에 넣어야 합니다.