4,633 stars · Apache-2.0, read from /blob/master/LICENSE — plain, nothing appended, and the holder is FILLED IN: 'Copyright 2017-2018 Yelp Inc.' One of only four of the twelve that name a real holder · v1.5.0 (2024-05-06), read from /releases/latest as a yearless '06 May 18:05' and settled by the PyPI project page ('Released: May 6, 2024'). Twenty-nine months old, against code pushed 2026-04-02 — a release date is not a code date · Track this in Scout
Lists the passwords and keys that were typed into code by mistake, and records the known ones in a baseline so only new findings are reported.
▶Repo detailsthe review · specs · pros & cons · install
What it is
detect-secrets is a command-line program that scans files for text shaped like a credential, using both pattern rules and a measure of randomness. Its distinguishing idea is the baseline file: the known findings are recorded once, so the tool can be made part of everyday work without a wall of old warnings.
What it is good for. Anyone who writes code without a colleague to review it. The dangerous case is not the password you remember putting in; it is the one from eight months ago in a file you have not opened since. Because it can run automatically before each save to the project history, it also stops the next one.
- The baseline file is the part that makes it usable. Without it, a scanner on an old project prints hundreds of findings nobody will read.
- Plain, unmodified Apache-2.0 with a real named holder: "Copyright 2017-2018 Yelp Inc." Four of today's twelve licence files manage that.
- It installs with one command, needs no server, and holds no data of its own.
- The newest release is v1.5.0 of 6 May 2024, nearly two and a half years old. The code itself is not stalled: the project pushed code on 2 April 2026. This is the pattern this report has learned to separate — a release date is not a code date, and an old release means the project has stopped publishing versions, not that it has stopped. It does mean a new rule added since May 2024 is not in the version you install.
- It declares no minimum Python version anywhere. There is no
python_requiresin its setup file and none on its package page. Its own test settings exercise Python 3.9 to 3.13, which is the only evidence available. - It finds and does not fix. A found key still has to be replaced by hand at the service that issued it, and removing it from the project's history is a separate and riskier job. It also cannot tell a real key from a random-looking test string, so some findings will be wrong.
gitleaks/gitleaksScans the same kinds of file and the whole project history, as one downloaded program with no Python needed, but without the baseline habit.
Track this in Scout
trufflesecurity/trufflehogFinds the same credentials and then calls the service to check which ones still work, so a finding means a live key rather than a suspicious string.
Track this in Scout- awslabs/git-secrets
Blocks a save to the project history when it spots a credential, as a short shell script tuned to Amazon keys; its last code landed on 17 September 2025.
Track this in Scout
pip install detect-secrets detect-secrets scan > .secrets.baseline detect-secrets audit .secrets.baseline
