返回更新列表
新发布Jul 21, 2026

secretlint v13.0.3

可插拔的 linting 工具,用于防止提交凭据。

分享

Secretlint Actions Status

Secretlint 是一款可插拔的 linting 工具,用于防止提交凭据。

Secretlint 是一款可插拔的 linting 工具,用于防止提交凭据。

特性

  • 扫描器:在项目中查找凭据并报告
  • 项目友好:轻松设置你的项目并集成 CI 服务
  • 提交前钩子:防止提交凭据文件
  • 可插拔:允许创建自定义规则和灵活配置
  • 文档:描述规则将其检测为机密的理由

快速演示

你可以在 https://secretlint.github.io/ 上查看 secretlint 的 linting 结果。

快速开始

你可以通过一条命令在项目中尝试使用 Secretlint。

如果你已经安装了 Docker:

docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"

如果你已经安装了 Node.js:

npx @secretlint/quick-start "**/*"

运行后, 如果你得到空结果且退出状态为 0,则你的项目是安全的。 否则,你会得到一些错误报告,说明你的项目包含作为原始数据的凭据。

secretlint 结果示例

如果你想要持续的安全性,请参阅以下安装指南并设置提交前钩子和 CI。

安装

使用 Docker

先决条件: 需要 Docker

使用我们的 Docker 容器 来获得一个包含 Node.js 和 secretlint 的环境,并以最快的速度下载并运行它们。

你可以通过以下命令使用 secretlint 检查当前目录下的所有文件:

docker run -v `pwd`:`pwd` -w `pwd` --rm -it secretlint/secretlint secretlint "**/*"

secretlint/secretlint docker 容器 设计为无需配置即可工作。

此 Docker 镜像内置了以下包:

更多详情,请参阅 secretlint 的 Dockerfile。

使用 Node.js

先决条件: 需要 Node.js 22+。

Secretlint 是用 JavaScript 编写的。 你可以使用 npm 安装 Secretlint:``` npm install secretlint @secretlint/secretlint-rule-preset-recommend --save-dev

然后你应该设置一个配置文件:```
npx secretlint --init

最后,你可以像这样对任何文件或目录运行 Secretlint:``` npx secretlint "**/*"

:memo: Secretlint 支持 [glob 模式](https://github.com/mrmlnc/fast-glob#basic-syntax),glob 模式应使用双引号包裹。

也可以使用 `npm install --global` 全局安装 Secretlint。但是,我们不推荐这样做,某些规则在全局环境下可能会失效。

### 使用单文件可执行二进制

**前置条件:** 无

你可以通过单文件可执行二进制使用 `secretlint` 命令,而无需安装 Node.js。

1. 从 [Releases 页面](https://github.com/secretlint/secretlint/releases) 下载最新的二进制文件
2. 将文件权限更改为可执行:`chmod +x ./secretlint`
3. 运行 `./secretlint --init` 创建配置文件
4. 运行 `./secretlint "**/*"` 对项目进行 lint

更多详情,请参阅 [publish/binary-compiler](https://github.com/secretlint/secretlint/blob/master/publish/binary-compiler) README。

## 用法

`secretlint --help` 显示用法。

    Secretlint CLI that scan secret/credential data.
    
    Usage
    $ secretlint [file|glob*]
    
    Note
    supported glob syntax is based on picomatch (the engine used by micromatch)
    https://github.com/micromatch/picomatch#globbing-features
    https://github.com/micromatch/micromatch#matching-features
    
    Options
    --init             setup config file. Create .secretlintrc.json file from your package.json
    --format           [String] formatter name. Default: "stylish". Available Formatter: checkstyle, compact, github, jslint-xml, junit, pretty-error, stylish, tap, unix, json, mask-result, table
    --output           [path:String] output file path that is written of reported result.
    --secretlintrc     [path:String] path to .secretlintrc config file. Default: .secretlintrc.*
    --secretlintignore [path:String] path to .secretlintignore file. Default: .secretlintignore
    --stdinFileName    [String] filename to process STDIN content. Some rules depend on filename to check content.
    --no-color         disable ANSI-color of output.
    --no-terminalLink  disable terminalLink of output.
    --no-maskSecrets   disable masking of secret values; secrets are masked by default.
    --no-glob          disable glob pattern interpretation; treat all inputs as literal file paths.
    --no-gitignore     disable .gitignore cascade respect; .gitignore files are
                       respected by default (since v13).
    
    Options for Developer
    --profile          Enable performance profile.
    --secretlintrcJSON [String] a JSON string of .secretlintrc. use JSON string instead of rc file.
    
    Experimental Options
    --locale            [String] locale tag for translating message. Default: en
    
    Examples
    # Scan a single file
    $ secretlint ./README.md

    # Scan all files (wrap glob in double quotes to avoid shell expansion)
    $ secretlint "**/*"
    $ secretlint "source/**/*.ini"

    # Treat inputs as literal paths (for SvelteKit (group) / Next.js [param] etc.)
    $ secretlint --no-glob "src/(auth)/login.ts"

    # Lint STDIN content (filename hint affects which rules apply)
    $ echo "SECRET" | secretlint --stdinFileName=secret.txt

    # Use a custom config file
    $ secretlint "**/*" --secretlintrc=.secretlintrc.custom.json

    # Scan files ignored by .gitignore (e.g. to verify build artifacts)
    $ secretlint --no-gitignore "dist/**/*"

    # Mask secrets in a file in-place
    $ secretlint .zsh_history --format=mask-result --output=.zsh_history

    # Output JSON for programmatic parsing
    $ secretlint "**/*" --format=json --output=secretlint-report.json

    # Output GitHub Actions annotations in CI
    $ secretlint "**/*" --format=github
    
    Exit Status
    Secretlint exits with the following values:
    
        - 0:
          - Linting succeeded, no errors found.
          - Found lint error but --output is specified.
        - 1:
          - Linting failed, errors found.
        - 2:
          - Unexpected error occurred, fatal error.


## 配置

Secretlint 有一个配置文件 `.secretlintrc.{json,yml,js}`。

- 文档:[配置 Secretlint](https://github.com/secretlint/secretlint/blob/master/docs/configuration.md)

运行 `secretlint --init` 后,你的目录中会生成一个 `.secretlintrc.json` 文件。

在其中,你会看到一些配置好的规则,如下所示:```json
{
  "rules": [
    {
      "id": "@secretlint/secretlint-rule-preset-recommend"
    }
  ]
}

id 属性是 secretlint 规则包的名称。

Secretlint 没有内置规则。 你需要添加一些规则,并且应该安装该包并将规则添加到 .secretlintrc 文件中。

每条规则都有相同的配置模式:

  • options:规则的选项定义。更多详情,请参阅每条规则的文档
  • disabled:如果 disabled 为 true,则禁用该规则
  • allowMessageIds:allowMessageIds 是一个消息 id 数组,用于抑制你希望忽略的错误报告
    • 消息 id 在每条规则中定义,请参阅规则文档

示例:options

例如,@secretlint/secretlint-rule-example 在 options 中有 allows。 这个 allows 选项定义了一个你希望忽略的 类 RegExp 字符串 列表。```json { "rules": [ { "id": "@secretlint/secretlint-rule-example", "options": { "allows": [ "/dummy_secret/i" ] } } ] }

当你使用像 `@secretlint/secretlint-rule-preset-recommend` 这样的预设时,你需要将选项放在 `rules` 中。

例如,`@secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-aws` 的一个选项```json5
{
  "rules": [
    {
      "id": "@secretlint/secretlint-rule-preset-recommend",
      "rules": [
        {
          "id": "@secretlint/secretlint-rule-aws",
            "options": {
              "allows": [
	            // it will be ignored
                "xxxx-xxxx-xxxx-xxxx-xxxx"
              ]
            }
        }
      ]
    }
  ]
}

示例:allowMessageIds

例如,你通过运行 secretlint 得到了以下错误报告:``` $ secretlint "**/*"

SECRET.txt 1:8 error [EXAMPLE_MESSAGE] found secret: SECRET @secretlint/secretlint-rule-example

✖ 1 problem (1 error, 0 warnings)

此错误的 message id 为 `EXAMPLE_MESSAGE`,位于 `@secretlint/secretlint-rule-example` 中。

分类