
Uma maneira amigável para empresas de detectar e prevenir segredos em código.
detect-secrets é um módulo com nome apropriado para (surpresa, surpresa) detectar segredos dentro de uma base de código.
No entanto, ao contrário de outros pacotes similares que focam apenas em encontrar segredos, este pacote foi projetado pensando no cliente empresarial: fornecendo um meio compatível com versões anteriores, sistemático de:
Dessa forma, você cria uma separação de preocupações: aceitando que pode atualmente haver segredos escondidos em seu grande repositório (isto é o que chamamos de baseline), mas impedindo que esse problema cresça, sem lidar com o esforço potencialmente gigantesco de remover os segredos existentes.
Ele faz isso executando saídas diff periódicas contra declarações regex heuristicamente criadas, para identificar se algum novo segredo foi commitado. Dessa forma, evita a sobrecarga de vasculhar todo o histórico do git, bem como a necessidade de escanear todo o repositório toda vez.
Para uma visão das mudanças recentes, consulte CHANGELOG.md.
Se você deseja contribuir, consulte CONTRIBUTING.md.
Para documentação mais detalhada, confira nossa outra documentação.
Crie uma baseline dos segredos potenciais atualmente encontrados em seu repositório git.```bash $ detect-secrets scan > .secrets.baseline
ou, para executá-lo a partir de um diretório diferente:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
Escaneando arquivos não rastreados pelo git:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### Adicionando Novos Segredos à Linha de Base:
Isso irá reexaminar sua base de código e:
1. Atualizar/melhorar sua linha de base para ser compatível com a versão mais recente,
2. Adicionar quaisquer novos segredos encontrados à sua linha de base,
3. Remover quaisquer segredos que não estejam mais em sua base de código
Isso também preservará quaisquer segredos rotulados que você tenha.```bash
$ detect-secrets scan --baseline .secrets.baseline
Para baselines mais antigos que a versão 0.9, apenas recrie-a.
Escaneando apenas arquivos em staged:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**Varrendo Todos os Arquivos Rastreados:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### Desativando Plugins:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
Se você quiser executar apenas um plugin específico, você pode fazer:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### Auditando uma Linha de Base:
Este é um passo opcional para rotular os resultados na sua linha de base. Pode ser usado para reduzir sua lista de verificação de segredos a migrar, ou para configurar melhor seus plugins a fim de melhorar sua relação sinal-ruído.```bash
$ detect-secrets audit .secrets.baseline
Uso Básico:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**Configuração Mais Avançada:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
Instale via [brew](https://brew.sh/):```bash
$ brew install detect-secrets
detect-secrets vem com três ferramentas diferentes, e muitas vezes há confusão sobre qual
usar. Use esta útil lista de verificação para ajudá-lo a decidir:
detect-secrets scan.detect-secrets-hook.detect-secrets audit.