detect-secrets 是一个恰如其名的模块,用于(惊喜,惊喜)检测代码库中的秘密。
然而,与其他仅专注于查找秘密的类似包不同,该包专为企业客户设计:提供一种向后兼容、系统化的方式:
这样,您就创建了一个关注点分离: 承认您的庞大仓库中可能目前隐藏着秘密(我们称之为_基线_),但避免这一问题进一步扩大,而无需处理将现有秘密迁出的巨大工作量。
它通过定期对启发式构建的正则表达式语句运行差异输出来实现这一点,以识别是否有新的秘密被提交。这样,它避免了挖掘所有git历史记录的开销,也无需每次都扫描整个仓库。
有关最近更改,请参阅CHANGELOG.md。
如果您希望贡献,请参阅CONTRIBUTING.md。
有关更详细的文档,请查看我们的其他文档。
在当前git仓库中创建潜在秘密的基线。```bash $ detect-secrets scan > .secrets.baseline
或者,从其他目录运行:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline
扫描非 git 跟踪的文件:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline
### 将新秘密添加到基线:
这将重新扫描你的代码库,并且:
1. 更新/升级你的基线以兼容最新版本,
2. 将任何新发现的秘密添加到你的基线,
3. 移除代码库中不再存在的任何秘密
这也会保留你已有的任何标记过的秘密。```bash
$ detect-secrets scan --baseline .secrets.baseline
对于早于 0.9 版本的基线,只需重新创建它。
仅扫描暂存文件:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
**扫描所有已跟踪的文件:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector
### 禁用插件:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector
如果你只想运行特定插件,可以执行:```bash
$ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data
### 审计基线:
这是一个可选步骤,用于标记基线中的结果。它可以用来缩小需要迁移的机密清单,或者更好地配置插件以提高信噪比。```bash
$ detect-secrets audit .secrets.baseline
基本用法:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings
secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')
import json print(json.dumps(secrets.json(), indent=2))
**更多高级配置:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings
secrets = SecretsCollection()
with transient_settings({
# Only run scans with only these plugins.
# This format is the same as the one that is saved in the generated baseline.
'plugins_used': [
# Example of configuring a built-in plugin
{
'name': 'Base64HighEntropyString',
'limit': 5.0,
},
# Example of using a custom plugin
{
'name': 'HippoDetector',
'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
},
],
# We can also specify whichever additional filters we want.
# This is an example of using the function `is_identified_by_ML_model` within the
# local file `./private-filters/example.py`.
'filters_used': [
{
'path': 'file://private-filters/example.py::is_identified_by_ML_model',
},
]
}) as settings:
# If we want to make any further adjustments to the created settings object (e.g.
# disabling default filters), we can do so as such.
settings.disable_filters(
'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
'detect_secrets.filters.heuristic.is_likely_id_string',
)
secrets.scan_file('test_data/config.ini')
$ pip install detect-secrets ✨🍰✨
通过 [brew](https://brew.sh/) 安装:```bash
$ brew install detect-secrets
detect-secrets 附带三种不同工具,常常会让人困惑该用哪一个。请使用这个便捷的清单来帮助您决定:
detect-secrets scan。detect-secrets-hook。detect-secrets audit。$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]
Scans a repository for secrets in code. The generated output is compatible
with detect-secrets-hook --baseline.
positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.
optional arguments:
-h, --help show this help message and exit
--string [STRING] Scans an individual string, and displays configured
plugins' verdict.
--only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions
are indeed non-secrets.
scan options:
--all-files Scan all files recursively (as compared to only
scanning git tracked files).
--baseline FILENAME If provided, will update existing baseline by
importing settings from it.
--force-use-all-plugins
If a baseline is provided, detect-secrets will default
to loading the plugins specified by that baseline.
However, this may also mean it doesn't perform the
scan with the latest plugins. If this flag is
provided, it will always use the latest plugins
--slim Slim baselines are created with the intention of
minimizing differences between commits. However, they
are not compatible with the audit functionality, and
slim baselines will need to be remade to be audited.
plugin options: Configure settings for each secret scanning ruleset. By default, all plugins are enabled unless explicitly disabled.