
기업 친화적인 코드 내 비밀 감지 및 방지 방법.
detect-secrets는 코드 베이스 내에서 (놀랍게도) 비밀(secret)을 탐지하기 위한 적절한 이름의 모듈입니다.
그러나 오직 비밀 찾기에만 초점을 맞춘 다른 유사 패키지와 달리, 이 패키지는 엔터프라이즈 클라이언트를 염두에 두고 설계되었습니다: 이전 버전과 호환되는 체계적인 수단을 제공합니다:
이런 방식으로, 관심사 분리를 만듭니다: 대규모 저장소에 현재 비밀이 숨어 있을 수 있다는 점을 인정하지만(이를 기준선(baseline) 이라고 합니다), 기존 비밀을 이동시키는 엄청난 노력을 들이지 않고 이 문제가 더 커지는 것을 방지합니다.
이는 주기적인 diff 출력을 경험적으로 작성된 정규식과 비교하여 새로운 비밀이 커밋되었는지 식별합니다. 이렇게 하면 모든 git 기록을 뒤질 필요가 없고 매번 전체 저장소를 스캔할 필요도 없습니다.
최근 변경 사항은 CHANGELOG.md를 참조하십시오.
기여하고 싶다면 CONTRIBUTING.md를 참조하십시오.
더 자세한 문서는 다른 문서를 확인하세요.
git 저장소에서 현재 발견된 잠재적 비밀의 기준선을 생성합니다.```bash $ detect-secrets scan > .secrets.baseline
또는, 다른 디렉토리에서 실행하려면:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
git 추적되지 않는 파일 스캔:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### 베이스라인에 새 비밀 추가:
코드베이스를 다시 스캔하여 다음을 수행합니다:
1. 베이스라인을 최신 버전과 호환되도록 업데이트/업그레이드합니다.
2. 발견된 모든 새 비밀을 베이스라인에 추가합니다.
3. 코드베이스에 더 이상 존재하지 않는 비밀을 제거합니다.
또한 레이블이 지정된 비밀은 유지됩니다.```bash
$ detect-secrets scan --baseline .secrets.baseline
버전 0.9보다 오래된 기준선은 그냥 다시 만드세요.
스테이징된 파일만 스캔:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**모든 추적된 파일 스캔 중:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### 플러그인 비활성화:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
오직 특정 플러그인을 실행하려면 다음을 수행하면 됩니다:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### 베이스라인 감사:
이는 베이스라인의 결과에 레이블을 지정하는 선택적 단계입니다. 이를 통해 마이그레이션할 시크릿 체크리스트를 좁히거나, 신호 대 잡음비를 개선하기 위해 플러그인을 더 잘 구성하는 데 사용할 수 있습니다.```bash
$ detect-secrets audit .secrets.baseline
기본 사용:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**고급 구성:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
[brew](https://brew.sh/)를 통해 설치:```bash
$ brew install detect-secrets
detect-secrets는 세 가지 도구를 제공하며, 어떤 것을 사용해야 할지 혼동이 있는 경우가 많습니다. 다음 편리한 체크리스트를 활용하여 결정하세요:
detect-secrets scan**을 사용하세요.detect-secrets-hook**을 사용하세요.detect-secrets audit**을 사용하세요.$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]
Scans a repository for secrets in code. The generated output is compatible
with detect-secrets-hook --baseline.
positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.
optional arguments:
-h, --help show this help message and exit
--string [STRING] Scans an individual string, and displays configured
plugins' verdict.
--only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions
are indeed non-secrets.