Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

secret checker #112

Open
NissesSenap opened this issue Dec 11, 2021 · 4 comments
Open

secret checker #112

NissesSenap opened this issue Dec 11, 2021 · 4 comments

Comments

@NissesSenap
Copy link
Contributor

Could something like gitleaks be useful as part of our default CI pipeline for checking for passwords being commited in git.
There are probably other tools but gitleaks looks a solid option at least.

https://github.com/zricethezav/gitleaks
https://github.com/zricethezav/gitleaks-action

@NissesSenap
Copy link
Contributor Author

Another option seems to be:
https://github.com/trufflesecurity/truffleHog
https://github.com/marketplace/actions/trufflehog-oss

There are probably a bunch more

@NissesSenap NissesSenap changed the title gitleaks secret checker secret checker May 29, 2022
@simongottschlag
Copy link
Member

Doesn't Horusec support this already?

@NissesSenap
Copy link
Contributor Author

Haven't checked, not impossible. But these are putposed built tools, so unless horusec uses them one of these are probably a better option

@simongottschlag
Copy link
Member

I think they have their own and integrates GitLeaks as well by default.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants