1999 stars · MIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2019 GitGuardian' · v1.55.0 of 2026-09-24, the yearless GitHub date settled by PyPI · Track this in Scout
Detects more than 500 kinds of hardcoded secret, as a pre-commit hook, a CI action or a command.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A small Python command-line program at 1,999 stars that checks files, code history, container images and packages for more than five hundred kinds of secret. It runs as a plain command, as a check before every save, or inside an automated build. New code landed on the morning this edition was written.
What it is good for. A small team that wants strong detection wired into the moment code is saved, without writing and maintaining its own list of patterns. It is also the easiest of these tools to put in front of an AI coding assistant: the newest version withholds the whole output when an assistant's tool call exposes a secret, rather than passing it along with a warning.
- MIT, read from the licence file and completely plain.
- The detection list is maintained by a company that does this for a living, so it covers far more kinds of key than a list you would write yourself.
- It fits into the places that matter: a check before saving, an automated build, and now three different AI coding assistants by name.
- The detection is a hosted service, not a local program, so your code leaves your machine. The README says plainly that it uses the company's public service to scan content. The company's stated position is that only information such as the time of the call, the size of the request and the mode is kept, and that files and secrets are not stored or shown on the dashboard. That is a promise about retention, not a design that makes sending unnecessary.
- An account is required. Nothing works without signing in first, so there is no offline or disconnected use.
- The free level is metered and the command-line tool is deliberately limited on it. The published lowest tier lists up to 25 developers, up to 500 historical detections and 10,000 service calls a month, and marks the command-line tool and the save-time check as "Limited", with the full version in the paid tiers.
- It puts somebody else's service on the path of your saves. A check that calls a service can hold up a save or a build when that service is slow. The newest version added a configurable timeout for exactly that reason.
- Keeping content in-house is possible, but only by buying the company's on-premises product — not by running this tool by itself.
gitleaks/gitleaksThe same job entirely on your own machine with no account and nothing sent anywhere, at the cost of never saying whether a found key still works; its maintainer states it is feature complete.
Track this in Scout
trufflesecurity/trufflehogAlso reaches the network, but to the key's own provider to test whether each credential is still live, and it needs no scanning account; AGPL-3.0 matters if it is redistributed.
Track this in Scout- Yelp/detect-secrets
Fully local and account-free, built around a saved list of already-known secrets so an old repository can be brought under control without every run failing; the weakest detection of the three.
Track this in Scout
python3 -m venv venv && source venv/bin/activate pip install ggshield ggshield auth login
