Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
detect-secrets — 기업 친화적인 코드 내 비밀 감지 및 방지 방법. | Kitploit
도구/GitHubGitHub/yelp/detect-secrets
Static AnalysisCode AnalysisDevSecOpsSecret DetectionSecret Detection #3위
GitHubyelp/detect-secrets

detect-secrets

기업 친화적인 코드 내 비밀 감지 및 방지 방법.

저장소 보기
4.6k564716개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Build Status PyPI version Homebrew PRs Welcome AMF

detect-secrets

소개

detect-secrets는 코드 베이스 내에서 (놀랍게도) 비밀(secret)을 탐지하기 위한 적절한 이름의 모듈입니다.

그러나 오직 비밀 찾기에만 초점을 맞춘 다른 유사 패키지와 달리, 이 패키지는 엔터프라이즈 클라이언트를 염두에 두고 설계되었습니다: 이전 버전과 호환되는 체계적인 수단을 제공합니다:

  1. 새로운 비밀이 코드 베이스에 들어오는 것을 방지하고,
  2. 그러한 방지 조치가 명시적으로 우회되었는지 탐지하며,
  3. 교체할 비밀 목록을 제공하고 더 안전한 저장소로 마이그레이션합니다.

이런 방식으로, 관심사 분리를 만듭니다: 대규모 저장소에 현재 비밀이 숨어 있을 수 있다는 점을 인정하지만(이를 기준선(baseline) 이라고 합니다), 기존 비밀을 이동시키는 엄청난 노력을 들이지 않고 이 문제가 더 커지는 것을 방지합니다.

이는 주기적인 diff 출력을 경험적으로 작성된 정규식과 비교하여 새로운 비밀이 커밋되었는지 식별합니다. 이렇게 하면 모든 git 기록을 뒤질 필요가 없고 매번 전체 저장소를 스캔할 필요도 없습니다.

최근 변경 사항은 CHANGELOG.md를 참조하십시오.

기여하고 싶다면 CONTRIBUTING.md를 참조하십시오.

더 자세한 문서는 다른 문서를 확인하세요.

예제

빠른 시작:

git 저장소에서 현재 발견된 잠재적 비밀의 기준선을 생성합니다.```bash $ detect-secrets scan > .secrets.baseline

또는, 다른 디렉토리에서 실행하려면:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline

git 추적되지 않는 파일 스캔:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline

### 베이스라인에 새 비밀 추가:

코드베이스를 다시 스캔하여 다음을 수행합니다:

1. 베이스라인을 최신 버전과 호환되도록 업데이트/업그레이드합니다.
2. 발견된 모든 새 비밀을 베이스라인에 추가합니다.
3. 코드베이스에 더 이상 존재하지 않는 비밀을 제거합니다.

또한 레이블이 지정된 비밀은 유지됩니다.```bash
$ detect-secrets scan --baseline .secrets.baseline

버전 0.9보다 오래된 기준선은 그냥 다시 만드세요.

새로 추가된 비밀 정보 알림 끄기:

스테이징된 파일만 스캔:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

**모든 추적된 파일 스캔 중:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

모든 활성화된 플러그인 보기:```bash

$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector

### 플러그인 비활성화:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector

오직 특정 플러그인을 실행하려면 다음을 수행하면 됩니다:```bash $ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data

### 베이스라인 감사:

이는 베이스라인의 결과에 레이블을 지정하는 선택적 단계입니다. 이를 통해 마이그레이션할 시크릿 체크리스트를 좁히거나, 신호 대 잡음비를 개선하기 위해 플러그인을 더 잘 구성하는 데 사용할 수 있습니다.```bash
$ detect-secrets audit .secrets.baseline

다른 Python 스크립트에서의 사용

기본 사용:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings

secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')

import json print(json.dumps(secrets.json(), indent=2))

**고급 구성:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings

secrets = SecretsCollection()
with transient_settings({
    # Only run scans with only these plugins.
    # This format is the same as the one that is saved in the generated baseline.
    'plugins_used': [
        # Example of configuring a built-in plugin
        {
            'name': 'Base64HighEntropyString',
            'limit': 5.0,
        },

        # Example of using a custom plugin
        {
            'name': 'HippoDetector',
            'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
        },
    ],

    # We can also specify whichever additional filters we want.
    # This is an example of using the function `is_identified_by_ML_model` within the
    # local file `./private-filters/example.py`.
    'filters_used': [
        {
            'path': 'file://private-filters/example.py::is_identified_by_ML_model',
        },
    ]
}) as settings:
    # If we want to make any further adjustments to the created settings object (e.g.
    # disabling default filters), we can do so as such.
    settings.disable_filters(
        'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
        'detect_secrets.filters.heuristic.is_likely_id_string',
    )

    secrets.scan_file('test_data/config.ini')

설치```bash

$ pip install detect-secrets ✨🍰✨

[brew](https://brew.sh/)를 통해 설치:```bash
$ brew install detect-secrets

사용법

detect-secrets는 세 가지 도구를 제공하며, 어떤 것을 사용해야 할지 혼동이 있는 경우가 많습니다. 다음 편리한 체크리스트를 활용하여 결정하세요:

  1. 베이스라인에 비밀을 추가하고 싶으신가요? 그렇다면 **detect-secrets scan**을 사용하세요.
  2. 베이스라인에 없는 새로운 비밀에 대해 경고를 받고 싶으신가요? 그렇다면 **detect-secrets-hook**을 사용하세요.
  3. 베이스라인 자체를 분석하고 계신가요? 그렇다면 **detect-secrets audit**을 사용하세요.

베이스라인에 비밀 추가하기```

$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]

Scans a repository for secrets in code. The generated output is compatible with detect-secrets-hook --baseline.

positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.

optional arguments: -h, --help show this help message and exit --string [STRING] Scans an individual string, and displays configured plugins' verdict. --only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions are indeed non-secrets.

도구 다운로드