Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
detect-secrets — 一种企业友好的检测和预防代码中机密信息的方式。 | Kitploit
工具/GitHubGitHub/yelp/detect-secrets
静态分析代码分析DevSecOps秘密检测秘密检测 分类第 3 名
GitHubyelp/detect-secrets

detect-secrets

一种企业友好的检测和预防代码中机密信息的方式。

查看仓库
4.6k564696个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Build Status PyPI version Homebrew PRs Welcome AMF

detect-secrets

关于

detect-secrets 是一个恰如其名的模块,用于(惊喜,惊喜)检测代码库中的秘密。

然而,与其他仅专注于查找秘密的类似包不同,该包专为企业客户设计:提供一种向后兼容、系统化的方式:

  1. 防止新的秘密进入代码库,
  2. 检测此类预防措施是否被明确绕过,以及
  3. 提供一个需要轮换并迁移到更安全存储的秘密清单。

这样,您就创建了一个关注点分离: 承认您的庞大仓库中可能目前隐藏着秘密(我们称之为_基线_),但避免这一问题进一步扩大,而无需处理将现有秘密迁出的巨大工作量。

它通过定期对启发式构建的正则表达式语句运行差异输出来实现这一点,以识别是否有新的秘密被提交。这样,它避免了挖掘所有git历史记录的开销,也无需每次都扫描整个仓库。

有关最近更改,请参阅CHANGELOG.md。

如果您希望贡献,请参阅CONTRIBUTING.md。

有关更详细的文档,请查看我们的其他文档。

示例

快速开始:

在当前git仓库中创建潜在秘密的基线。```bash $ detect-secrets scan > .secrets.baseline

或者,从其他目录运行:```bash
$ detect-secrets -C /path/to/directory scan > /path/to/directory/.secrets.baseline

扫描非 git 跟踪的文件:```bash $ detect-secrets scan test_data/ --all-files > .secrets.baseline

### 将新秘密添加到基线:

这将重新扫描你的代码库,并且:

1. 更新/升级你的基线以兼容最新版本,
2. 将任何新发现的秘密添加到你的基线,
3. 移除代码库中不再存在的任何秘密

这也会保留你已有的任何标记过的秘密。```bash
$ detect-secrets scan --baseline .secrets.baseline

对于早于 0.9 版本的基线,只需重新创建它。

关闭新增秘密的警报:

仅扫描暂存文件:```bash $ git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

**扫描所有已跟踪的文件:**```bash
$ git ls-files -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline

查看所有启用的插件:```bash

$ detect-secrets scan --list-all-plugins ArtifactoryDetector AWSKeyDetector AzureStorageKeyDetector BasicAuthDetector CloudantDetector DiscordBotTokenDetector GitHubTokenDetector GitLabTokenDetector Base64HighEntropyString HexHighEntropyString IbmCloudIamDetector IbmCosHmacDetector IPPublicDetector JwtTokenDetector KeywordDetector MailchimpDetector NpmDetector OpenAIDetector PrivateKeyDetector PypiTokenDetector SendGridDetector SlackDetector SoftlayerDetector SquareOAuthDetector StripeDetector TelegramBotTokenDetector TwilioKeyDetector

### 禁用插件:```bash
$ detect-secrets scan --disable-plugin KeywordDetector --disable-plugin AWSKeyDetector

如果你只想运行特定插件,可以执行:```bash $ detect-secrets scan --list-all-plugins |
grep -v 'BasicAuthDetector' |
sed "s#^#--disable-plugin #g" |
xargs detect-secrets scan test_data

### 审计基线:

这是一个可选步骤,用于标记基线中的结果。它可以用来缩小需要迁移的机密清单,或者更好地配置插件以提高信噪比。```bash
$ detect-secrets audit .secrets.baseline

在其他 Python 脚本中的使用

基本用法:```python from detect_secrets import SecretsCollection from detect_secrets.settings import default_settings

secrets = SecretsCollection() with default_settings(): secrets.scan_file('test_data/config.ini')

import json print(json.dumps(secrets.json(), indent=2))

**更多高级配置:**```python
from detect_secrets import SecretsCollection
from detect_secrets.settings import transient_settings

secrets = SecretsCollection()
with transient_settings({
    # Only run scans with only these plugins.
    # This format is the same as the one that is saved in the generated baseline.
    'plugins_used': [
        # Example of configuring a built-in plugin
        {
            'name': 'Base64HighEntropyString',
            'limit': 5.0,
        },

        # Example of using a custom plugin
        {
            'name': 'HippoDetector',
            'path': 'file:///Users/aaronloo/Documents/github/detect-secrets/testing/plugins.py',
        },
    ],

    # We can also specify whichever additional filters we want.
    # This is an example of using the function `is_identified_by_ML_model` within the
    # local file `./private-filters/example.py`.
    'filters_used': [
        {
            'path': 'file://private-filters/example.py::is_identified_by_ML_model',
        },
    ]
}) as settings:
    # If we want to make any further adjustments to the created settings object (e.g.
    # disabling default filters), we can do so as such.
    settings.disable_filters(
        'detect_secrets.filters.heuristic.is_prefixed_with_dollar_sign',
        'detect_secrets.filters.heuristic.is_likely_id_string',
    )

    secrets.scan_file('test_data/config.ini')

安装```bash

$ pip install detect-secrets ✨🍰✨

通过 [brew](https://brew.sh/) 安装:```bash
$ brew install detect-secrets

用法

detect-secrets 附带三种不同工具,常常会让人困惑该用哪一个。请使用这个便捷的清单来帮助您决定:

  1. 您想向基线添加秘密吗?如果是,请使用 detect-secrets scan。
  2. 您想对不在基线中的新秘密发出警报吗?如果是,请使用 detect-secrets-hook。
  3. 您正在分析基线本身吗?如果是,请使用 detect-secrets audit。

向基线添加秘密```

$ detect-secrets scan --help usage: detect-secrets scan [-h] [--string [STRING]] [--only-allowlisted] [--all-files] [--baseline FILENAME] [--force-use-all-plugins] [--slim] [--list-all-plugins] [-p PLUGIN] [--base64-limit [BASE64_LIMIT]] [--hex-limit [HEX_LIMIT]] [--disable-plugin DISABLE_PLUGIN] [-n | --only-verified] [--exclude-lines EXCLUDE_LINES] [--exclude-files EXCLUDE_FILES] [--exclude-secrets EXCLUDE_SECRETS] [--word-list WORD_LIST_FILE] [-f FILTER] [--disable-filter DISABLE_FILTER] [path [path ...]]

Scans a repository for secrets in code. The generated output is compatible with detect-secrets-hook --baseline.

positional arguments: path Scans the entire codebase and outputs a snapshot of currently identified secrets.

optional arguments: -h, --help show this help message and exit --string [STRING] Scans an individual string, and displays configured plugins' verdict. --only-allowlisted Only scans the lines that are flagged with allowlist secret. This helps verify that individual exceptions are indeed non-secrets.

scan options: --all-files Scan all files recursively (as compared to only scanning git tracked files). --baseline FILENAME If provided, will update existing baseline by importing settings from it. --force-use-all-plugins If a baseline is provided, detect-secrets will default to loading the plugins specified by that baseline. However, this may also mean it doesn't perform the scan with the latest plugins. If this flag is provided, it will always use the latest plugins --slim Slim baselines are created with the intention of minimizing differences between commits. However, they are not compatible with the audit functionality, and slim baselines will need to be remade to be audited.

plugin options: Configure settings for each secret scanning ruleset. By default, all plugins are enabled unless explicitly disabled.

下载工具