A lightweight secret and token scanner for git repositories. Scans commit diffs for leaked API keys, credentials, private keys, and other sensitive values.
- 33 named rules — AWS, GCP, Azure, GitHub/GitLab tokens, Stripe, SendGrid, Twilio, Slack, Discord, PEM/PGP keys, JWTs, DB connection strings, and more
- Entropy detection — catches high-entropy strings that evade named rules
- Flexible scan depth — latest commit, since last scan, last N commits, or full history
- Branch targeting — scan a specific branch, HEAD, or all branches at once
- Background monitoring — auto-scan repos on a configurable interval
- Resolve findings — dismiss false positives so they stop cluttering results
- Secret masking — matched values are stored and displayed masked
cd backend
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
uvicorn app.main:app --reloaddocker compose up --build- Add a repo — paste a local path or GitHub URL in the Repositories tab and press Enter
- Scan — choose branch and depth, then click "Scan now"
- Review findings — click any scan row to open the findings panel
- Resolve — click "Resolve" on a finding to dismiss it; toggle "Show resolved" to review dismissed items
- Monitor — click the monitor button on a repo to enable automatic background scanning
cd backend
pytest tests/ -vAll 80 tests should pass.
- Backend — FastAPI, SQLAlchemy, GitPython, APScheduler
- Database — SQLite (dev) / PostgreSQL (prod)
- Frontend — Vanilla JS, Tailwind CSS CDN
MIT