Security and privacy · Edition No. 43 · 7 Oct 2026

Yelp/detect-secrets

Lists the passwords and keys that were typed into code by mistake, and records the known ones in a baseline so only new findings are reported.

← Security and privacyRead the whole edition →

4,633 stars · Apache-2.0, read from /blob/master/LICENSE — plain, nothing appended, and the holder is FILLED IN: 'Copyright 2017-2018 Yelp Inc.' One of only four of the twelve that name a real holder · v1.5.0 (2024-05-06), read from /releases/latest as a yearless '06 May 18:05' and settled by the PyPI project page ('Released: May 6, 2024'). Twenty-nine months old, against code pushed 2026-04-02 — a release date is not a code date · Track this in Scout

Lists the passwords and keys that were typed into code by mistake, and records the known ones in a baseline so only new findings are reported.

▶Repo detailsthe review · specs · pros & cons · install

What it is

detect-secrets is a command-line program that scans files for text shaped like a credential, using both pattern rules and a measure of randomness. Its distinguishing idea is the baseline file: the known findings are recorded once, so the tool can be made part of everyday work without a wall of old warnings.

What it is good for. Anyone who writes code without a colleague to review it. The dangerous case is not the password you remember putting in; it is the one from eight months ago in a file you have not opened since. Because it can run automatically before each save to the project history, it also stops the next one.

Stars4,633
LicenceApache-2.0, read from /blob/master/LICENSE — plain, nothing appended, and the holder is FILLED IN: 'Copyright 2017-2018 Yelp Inc.' One of only four of the twelve that name a real holder
Latestv1.5.0 (2024-05-06), read from /releases/latest as a yearless '06 May 18:05' and settled by the PyPI project page ('Released: May 6, 2024'). Twenty-nine months old, against code pushed 2026-04-02 — a release date is not a code date
Good
  • The baseline file is the part that makes it usable. Without it, a scanner on an old project prints hundreds of findings nobody will read.
  • Plain, unmodified Apache-2.0 with a real named holder: "Copyright 2017-2018 Yelp Inc." Four of today's twelve licence files manage that.
  • It installs with one command, needs no server, and holds no data of its own.
Watch for
  • The newest release is v1.5.0 of 6 May 2024, nearly two and a half years old. The code itself is not stalled: the project pushed code on 2 April 2026. This is the pattern this report has learned to separate — a release date is not a code date, and an old release means the project has stopped publishing versions, not that it has stopped. It does mean a new rule added since May 2024 is not in the version you install.
  • It declares no minimum Python version anywhere. There is no python_requires in its setup file and none on its package page. Its own test settings exercise Python 3.9 to 3.13, which is the only evidence available.
  • It finds and does not fix. A found key still has to be replaced by hand at the service that issued it, and removing it from the project's history is a separate and riskier job. It also cannot tell a real key from a random-looking test string, so some findings will be wrong.
Similar repositories
Install
pip install detect-secrets
detect-secrets scan > .secrets.baseline
detect-secrets audit .secrets.baseline
Screenshots
Yelp/detect-secrets: GitHub preview card

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.