[{"data":1,"prerenderedAt":748},["ShallowReactive",2],{"tool-detect-secrets-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":13,"about":20,"sources":29,"cover":57,"og":58,"expertise":59,"locales":60,"lang":61,"title":64,"description":65,"coverAlt":66,"url":32,"pricing":67,"kind":68,"metaTitle":69,"takeaways":70,"faq":76,"toc":89,"blocks":114,"others":541},"detect-secrets","2026-08-03",10,"security",[9,10,11,12],"Secret scanning","Pre-commit","Git","DevSecOps",[4,14,15,16,17,18,19],"detect-secrets vs gitleaks","detect-secrets baseline","secret scanning tools comparison","gitleaks vs trufflehog","rotate leaked api keys","pre-commit secret hook",[21,24,26],{"name":22,"url":23},"Yelp","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FYelp",{"name":11,"url":25},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGit",{"name":27,"url":28},"Apache License","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FApache_License",[30,33,36,39,42,45,48,51,54],{"title":31,"url":32},"Yelp\u002Fdetect-secrets: README and usage","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets",{"title":34,"url":35},"Yelp\u002Fdetect-secrets: CHANGELOG (v1.5.0, 6 May 2024)","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Fblob\u002Fmaster\u002FCHANGELOG.md",{"title":37,"url":38},"Yelp\u002Fdetect-secrets: plugin and verification documentation","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Fblob\u002Fmaster\u002Fdocs\u002Fplugins.md",{"title":40,"url":41},"detect-secrets 1.5.0 on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Fdetect-secrets\u002F",{"title":43,"url":44},"Yelp\u002Fdetect-secrets: releases","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\u002Freleases",{"title":46,"url":47},"Gitleaks README (MIT, Go)","https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks",{"title":49,"url":50},"TruffleHog README (AGPL-3.0, credential verification)","https:\u002F\u002Fgithub.com\u002Ftrufflesecurity\u002Ftrufflehog",{"title":52,"url":53},"GitHub Docs: About secret scanning","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsecret-scanning\u002Fintroduction\u002Fabout-secret-scanning",{"title":55,"url":56},"betterleaks\u002Fbetterleaks","https:\u002F\u002Fgithub.com\u002Fbetterleaks\u002Fbetterleaks","\u002Fimages\u002Fblog\u002Fdetect-secrets\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fdetect-secrets\u002Fog.jpg","ai-engineer",[61,62,63],"en","de","hu","detect-secrets: secret scanning with a committed baseline","What detect-secrets does, how its committed baseline differs from gitleaks and TruffleHog, why verification calls matter in CI, and where the tool stops.","Diagram: files pass through transformers, plugins, filters and verification into a JSON baseline, which then feeds the pre-commit gate and the audit session.","Apache-2.0","Secret detection","detect-secrets: scanning with a baseline · Balázs Csorba",[71,72,73,74,75],"detect-secrets accepts that a repository may already contain secrets. A committed .secrets.baseline records the findings and the hook blocks only new ones, so adoption needs no clean-up project first.","Precision comes from labels rather than better regexes: detect-secrets audit plus --stats is the measurement, and --exclude-files, --exclude-lines, --word-list and the two entropy thresholds are the tuning dials.","Verification is on by default and calls the issuing service over the network. That cuts false positives hard and needs a deliberate decision in an air-gapped CI runner.","Version 1.5.0 from 6 May 2024 is still the newest release, with Python 3.13 support sitting unreleased on master. Pin the version and do not plan new automation around new detectors.","gitleaks is the simpler pick for a new repository and TruffleHog is the one that confirms whether a key is still live. detect-secrets owns the audit and rotation workflow the other two do not have.",[77,80,83,86],{"q":78,"a":79},"What is a .secrets.baseline and why is it committed?","It is a JSON file listing every secret the tool currently finds, together with the plugin and filter configuration and a hash of each finding. Committing it gives the pre-commit hook a stable reference: findings already listed are ignored, anything new fails the commit. It doubles as the migration checklist, because detect-secrets audit labels which entries are real secrets.",{"q":81,"a":82},"Does detect-secrets find secrets in Git history?","No, and that is deliberate: it scans the Git-tracked files in the working tree, so a credential that was committed and removed years ago is invisible to it. The README frames this as avoiding the cost of walking history on every run. History needs a separate one-off scan with gitleaks or TruffleHog, plus a rewrite if the credential was ever valid.",{"q":84,"a":85},"What do --only-verified and --no-verify do?","By default the tool tries to verify every finding by calling the service that issued the credential, using the techniques from the keyhacks project. --only-verified reports just the credentials the service confirmed, which is precise but needs outbound network access; -n (--no-verify) turns verification off entirely, which is what an air-gapped CI runner needs.",{"q":87,"a":88},"Is detect-secrets still maintained?","Stable, but quiet: 1.5.0, published on 6 May 2024, is both the latest release on PyPI and the newest GitHub tag. Commits continue at a low rate, the last one on master is from April 2026, and Python 3.13 support was merged in January 2025 without a release. Treat it as maintained rather than developed, pin v1.5.0, and read master if you need the newer Python.",[90,93,96,99,102,105,108,111],{"id":91,"title":92},"what-it-is","What it is",{"id":94,"title":95},"how-it-works","How it works",{"id":97,"title":98},"getting-started","Getting started",{"id":100,"title":101},"signal-vs-noise","Signal and noise",{"id":103,"title":104},"rotation-workflow","The rotation workflow",{"id":106,"title":107},"where-it-shingles","Where it shingled badly",{"id":109,"title":110},"verdict","Verdict",{"id":112,"title":113},"sources","Sources",[115,119,128,131,147,225,226,229,238,241,252,253,264,266,269,271,286,301,302,305,354,367,368,379,391,394,395,398,486,489,490,493,505,511,512],{"type":116,"content":117},"paragraph",[118],"detect-secrets is Yelp's Apache-2.0 secret scanner for Git repositories, and the idea that sets it apart from every other one is the baseline. You accept that a repository may already contain secrets, you record what is in there, and from that point the tool blocks only new ones. It is a deliberately unglamorous design and it remains the right shape for a codebase nobody has time to clean. The catch is the maintenance state: 1.5.0 from 6 May 2024 is still the newest release, and the last commit on master landed in April 2026.",{"type":116,"content":120},[121,122,127],"It belongs in the same slot as gitleaks and TruffleHog, in front of the commit or the pipeline. It is not a secret manager: it finds, it blocks, and it hands you a list of what to rotate. GitHub's own secret scanning covers repositories hosted on GitHub and needs GitHub Secret Protection before it will scan private ones, and it does nothing for GitLab, Bitbucket or a self-hosted forge. For where a scanner belongs in an agent's sandboxing story, see ",{"tag":123,"to":124,"children":125},"link","\u002Fblog\u002Fsandboxing-coding-agents-ci-checklist",[126],"sandboxing coding agents in CI",".",{"type":129,"level":130,"id":91,"text":92},"heading",2,{"type":116,"content":132},[133,134,138,139,142,143,146],"The package ships three commands, and the README is unusually clear about which one to use when. ",{"tag":135,"children":136},"code",[137],"detect-secrets scan"," creates or updates the baseline, ",{"tag":135,"children":140},[141],"detect-secrets-hook"," checks a list of files against it and exits non-zero on anything new, and ",{"tag":135,"children":144},[145],"detect-secrets audit"," is an interactive session that labels findings as real secrets or false positives and writes those labels back into the baseline.",{"type":148,"ordered":149,"items":150},"list",false,[151,157,169,185,202,207,216],[152,156],{"tag":153,"children":154},"strong",[155],"Python, Apache-2.0, version 1.5.0",", published on 6 May 2024, with 4,649 stars and 573 forks. The PyPI classifier says production\u002Fstable, which describes the API more than the roadmap.",[158,161,162,165,166,127],{"tag":153,"children":159},[160],"27 detectors"," listed by ",{"tag":135,"children":163},[164],"--list-all-plugins",", in three families: regex rules for AWS, GitHub, GitLab, Slack, Stripe, OpenAI, npm, PyPI, Telegram, Twilio and private keys; entropy detectors for Base64 and hex strings; and a keyword detector that ignores the value and flags assignments to names such as ",{"tag":135,"children":167},[168],"password",[170,173,174,177,178,177,181,184],{"tag":153,"children":171},[172],"Filters run after the plugins"," and decide what survives: ",{"tag":135,"children":175},[176],"--exclude-files",", ",{"tag":135,"children":179},[180],"--exclude-lines",{"tag":135,"children":182},[183],"--exclude-secrets",", a word list of your own identifiers, and inline pragmas.",[186,189,190,193,194,197,198,201],{"tag":153,"children":187},[188],"Verification is on by default",". For patterns it recognises, the tool calls the issuing service to ask whether the credential is real. ",{"tag":135,"children":191},[192],"-n"," (",{"tag":135,"children":195},[196],"--no-verify",") turns that off, ",{"tag":135,"children":199},[200],"--only-verified"," keeps only the confirmed ones.",[203,206],{"tag":153,"children":204},[205],"The baseline is the entire state",". It is a JSON file committed to the repository that stores the plugin and filter configuration plus a hashed fingerprint for every finding.",[208,211,212,215],{"tag":153,"children":209},[210],"Audit is the measurement",". Labels make ",{"tag":135,"children":213},[214],"detect-secrets audit --stats"," report how well each detector performed on your code, which is the only way to tune it honestly.",[217,220,221,224],{"tag":153,"children":218},[219],"Three deployment shapes",": a pre-commit hook, a CI job over staged or tracked files, or a library through ",{"tag":135,"children":222},[223],"SecretsCollection"," when you need it inside your own tooling.",{"type":129,"level":130,"id":94,"text":95},{"type":116,"content":227},[228],"The engine has two stages. Plugins produce potential secrets, then filters and the verification policy decide which of them are reported. Transformers normalise the input first, which is why INI, YAML, XML and Markdown files can be scanned line by line without special cases per format. A serialisable settings object ties the two halves together and travels inside the baseline, so a scan on a CI runner uses exactly the configuration that produced the file on a laptop.",{"type":230,"attrs":231,"inner":235,"caption":236},"diagram",{"viewBox":232,"role":233,"aria-labelledby":234},"0 0 720 300","img","d1-ds-t d1-ds-d","\u003Ctitle id=\"d1-ds-t\">detect-secrets: scan once, gate every commit\u003C\u002Ftitle>\u003Cdesc id=\"d1-ds-d\">Git-tracked files pass through transformers, plugins and filters, verification makes a network call where a plugin supports it, and the result is written to a committed JSON baseline. The pre-commit hook and the audit session both read that baseline.\u003C\u002Fdesc>\u003Ctext x=\"20\" y=\"28\" class=\"d-title\">detect-secrets: scan once, gate every commit\u003C\u002Ftext>\u003Ctext x=\"700\" y=\"28\" text-anchor=\"end\" class=\"d-label\">detect-secrets docs\u003C\u002Ftext>\u003Ctext x=\"20\" y=\"56\" class=\"d-label\">ONCE PER BASELINE\u003C\u002Ftext>\u003Crect x=\"20\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"80\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Tracked files\u003C\u002Ftext>\u003Ctext x=\"80\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">worktree, git\u003C\u002Ftext>\u003Cpath d=\"M140 102 H152\" class=\"d-line\" \u002F>\u003Cpath d=\"M160 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"160\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"220\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Transformers\u003C\u002Ftext>\u003Ctext x=\"220\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">ini, yaml, xml\u003C\u002Ftext>\u003Cpath d=\"M280 102 H292\" class=\"d-line\" \u002F>\u003Cpath d=\"M300 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"300\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"360\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Plugins\u003C\u002Ftext>\u003Ctext x=\"360\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">regex, entropy\u003C\u002Ftext>\u003Cpath d=\"M420 102 H432\" class=\"d-line\" \u002F>\u003Cpath d=\"M440 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"440\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"500\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Filters\u003C\u002Ftext>\u003Ctext x=\"500\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">plus verification\u003C\u002Ftext>\u003Cpath d=\"M560 102 H572\" class=\"d-line\" \u002F>\u003Cpath d=\"M580 102 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"580\" y=\"70\" width=\"120\" height=\"64\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"640\" y=\"98\" text-anchor=\"middle\" class=\"d-text\">Baseline\u003C\u002Ftext>\u003Ctext x=\"640\" y=\"119\" text-anchor=\"middle\" class=\"d-small\">json, hashed\u003C\u002Ftext>\u003Ctext x=\"20\" y=\"172\" class=\"d-label\">EVERY COMMIT\u003C\u002Ftext>\u003Cpath d=\"M600 134 C600 162 185 160 185 176\" class=\"d-line\" \u002F>\u003Cpath d=\"M185 186 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Cpath d=\"M660 134 C660 162 535 160 535 176\" class=\"d-line\" \u002F>\u003Cpath d=\"M535 186 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Crect x=\"20\" y=\"186\" width=\"330\" height=\"64\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"185\" y=\"214\" text-anchor=\"middle\" class=\"d-text\">detect-secrets-hook\u003C\u002Ftext>\u003Ctext x=\"185\" y=\"235\" text-anchor=\"middle\" class=\"d-small\">staged files, exit 1\u003C\u002Ftext>\u003Crect x=\"370\" y=\"186\" width=\"330\" height=\"64\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"535\" y=\"214\" text-anchor=\"middle\" class=\"d-text\">detect-secrets audit\u003C\u002Ftext>\u003Ctext x=\"535\" y=\"235\" text-anchor=\"middle\" class=\"d-small\">labels real or false\u003C\u002Ftext>",[237],"One scan produces the baseline; the hook and the audit session only read it.",{"type":116,"content":239},[240],"Verification is the mechanism that decides whether the tool is usable in practice. Since 0.12.4 a plugin can implement a verify function that asks the issuing service whether the credential is live, using the techniques catalogued by the keyhacks project. Verification is also handed five lines of context on either side of the match, because the research behind that choice found an 80 per cent chance of finding the second half of a multi-factor secret nearby. The gain in precision is large; the cost is an outbound network request on every commit that touches a matching line.",{"type":116,"content":242},[243,244,247,248,251],"The baseline then does the separating of concerns. ",{"tag":135,"children":245},[246],"detect-secrets scan --baseline .secrets.baseline"," rescans the tree, migrates the file to the current format, adds new findings, drops the ones that disappeared and preserves the audit labels, so its diff stays small enough to review. The ",{"tag":135,"children":249},[250],"--slim"," flag pushes that further and minimises the diff between commits, at the cost of the audit feature: slim baselines cannot be audited later, so they have to be remade.",{"type":129,"level":130,"id":97,"text":98},{"type":116,"content":254},[255,256,259,260,263],"Installation is ",{"tag":135,"children":257},[258],"pip install detect-secrets"," or ",{"tag":135,"children":261},[262],"brew install detect-secrets",". Version 1.5.0 supports Python 3.8 to 3.12 and dropped 3.6 and 3.7; master already carries Python 3.13 support, but that change has not shipped in a release, so a 3.13 environment has to install from git. The documented setup is a pre-commit hook with the baseline as an argument.",{"type":135,"code":265},"# .pre-commit-config.yaml\nrepos:\n  - repo: https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets\n    rev: v1.5.0\n    hooks:\n      - id: detect-secrets\n        args: ['--baseline', '.secrets.baseline']\n        exclude: package.lock.json",{"type":116,"content":267},[268],"Then create the baseline once, from the repository root, and commit it. From that moment the hook runs on every commit and fails only on lines that are not in the file. The first scan of an old repository can return thousands of findings, which is precisely the situation the baseline exists for.",{"type":135,"code":270},"pip install detect-secrets\n\n# once, from the repository root: record what is already there\ndetect-secrets scan > .secrets.baseline\n\n# after real leaks are rotated, or the repo legitimately grew\ndetect-secrets scan --baseline .secrets.baseline\n\n# label findings once, then keep the labels\ndetect-secrets audit .secrets.baseline\n\n# CI: fail the build on anything the baseline does not list\ngit diff --staged --name-only -z | xargs -0 \\\n  detect-secrets-hook --baseline .secrets.baseline",{"type":116,"content":272},[273,274,277,278,281,282,285],"Inline allowlisting is the other half of the workflow. A line ending in ",{"tag":135,"children":275},[276],"# pragma: allowlist secret",", or a line carrying ",{"tag":135,"children":279},[280],"\u002F\u002F pragma: allowlist nextline secret"," above it, is skipped without touching the baseline, which is the right tool for a test fixture or a documentation example. ",{"tag":135,"children":283},[284],"detect-secrets scan --only-allowlisted"," inverts the check and reports exactly those lines, so the pragma cannot quietly become the place where real credentials hide.",{"type":287,"variant":288,"title":289,"body":290},"callout","warn","Two things to settle before this goes into a build",[291,296],[292,293,295],"Verification makes outbound requests to third-party APIs on every machine that runs the hook. In a locked-down CI network that either slows the scan down or fails it, so decide deliberately between ",{"tag":135,"children":294},[192]," in CI and a proxy allowlist for the services you verify against.",[297,300],{"tag":135,"children":298},[299],"detect-secrets audit --report"," can print the secret values themselves. Run the audit on a laptop, and never paste its output into a ticket, a chat or a CI log. The baseline only ever stores hashes.",{"type":129,"level":130,"id":100,"text":101},{"type":116,"content":303},[304],"Out of the box the detectors are tuned for a generic repository, and the work that follows is tuning them for yours. The audit step is not a formality: it is the only measurement available, and it is manual.",{"type":148,"ordered":306,"items":307},true,[308,313,324,334,344,348],[309,310,312],"Generate the baseline, then label a representative sample with ",{"tag":135,"children":311},[145],". Nothing else in this list works without it.",[314,315,318,319,321,322,127],"Read the statistics. Detectors that produce mostly false positives get disabled with ",{"tag":135,"children":316},[317],"--disable-plugin",", or narrowed with ",{"tag":135,"children":320},[176]," and ",{"tag":135,"children":323},[180],[325,326,329,330,333],"Move the entropy thresholds instead of deleting detectors: ",{"tag":135,"children":327},[328],"--base64-limit"," defaults to 4.5 and ",{"tag":135,"children":331},[332],"--hex-limit"," to 3.0, and those are the two dials the tool exposes.",[335,336,339,340,343],"Add a word list of your own identifiers with ",{"tag":135,"children":337},[338],"--word-list",", which needs the ",{"tag":135,"children":341},[342],"detect-secrets[word_list]"," extra.",[345,346,127],"Consider the optional gibberish model for secrets that look like words. It is not on by default because it also ignores values such as ",{"tag":135,"children":347},[168],[349,350,353],"Re-scan with ",{"tag":135,"children":351},[352],"--baseline"," after every change and read the diff of the baseline file. A shrinking diff means less noise, not fewer secrets.",{"type":287,"variant":355,"title":356,"body":357},"tip","Ship the gate in two steps",[358],[359,360,362,363,366],"Run the hook in report-only mode for a sprint and count findings per thousand lines of changed code. Only then make it blocking. A gate that cries wolf gets bypassed with ",{"tag":135,"children":361},[192],", a ",{"tag":135,"children":364},[365],"SKIP"," prefix or a force-push, and a bypassed gate is worse than no gate because the team believes it is covered.",{"type":129,"level":130,"id":103,"text":104},{"type":116,"content":369},[370,371,374,375,378],"The third command is what pays for the tuning, and it is not about finding anything new. Audit labels write ",{"tag":135,"children":372},[373],"is_secret"," into the baseline; combined with ",{"tag":135,"children":376},[377],"--report"," they produce the list of credentials still sitting in the repository that need replacing. That list is what turns a scan into a security task with an owner and a deadline.",{"type":148,"ordered":149,"items":380},[381,383,385,389],[382],"Label first, report second. A finding marked as a real secret in the baseline is an entry in the migration list.",[384],"Rotate at the provider, not in the repository. Deleting the file changes nothing about whether the key works.",[349,386,388],{"tag":135,"children":387},[352]," afterwards. The finding disappears from the file, and that diff is the evidence the migration finished.",[390],"Keep history scanning separate. The tool never looks at old commits, so a rewrite or a one-off history scan is a different job.",{"type":116,"content":392},[393],"This is the separation of concerns the README describes, and it is still the best argument for the tool. It does not demand that you clean the repository before it becomes useful, which is exactly what a scanner bolted onto a mature codebase usually demands.",{"type":129,"level":130,"id":106,"text":107},{"type":116,"content":396},[397],"The weaknesses are structural rather than cosmetic. It will not catch a multi-line secret or a default password the keyword detector does not recognise, and the README says so in a section titled Caveats. It does not scan Git history by design, so a credential that was committed and deleted years ago is invisible to it. Custom plugins are loaded by importing an arbitrary file, which the plugin documentation flags as a security assumption of its own. And the project is in maintenance mode: 1.5.0 from May 2024 is still the newest tag, Python 3.13 support has been sitting on master since January 2025, and the issue tracker holds 184 open issues.",{"type":399,"head":400,"rows":424},"table",[401,409,414,419],[402,403,403,404,405,406,407,403,408],"A","t","r","i","b","u","e",[410,408,403,408,411,403,412,413,408,411,404,408,403,413],"d","c","-","s",[415,405,403,416,408,417,418,413],"g","l","a","k",[420,404,407,421,421,416,408,422,423,415],"T","f","H","o",[425,441,447,458,467,476],[426,429,434,437],[427,405,411,408,428,411,408],"L","n",[402,430,417,411,431,408,412,432,127,433],"p","h","2","0",[435,436,420],"M","I",[402,438,439,427,412,440,127,433],"G","P","3",[442,443,445,446],[427,417,428,415,407,417,415,408],[439,444,403,431,423,428],"y",[438,423],[438,423],[448,452,454,456],[449,408,403,408,411,403,405,423,428,450,451,423,410,408,416],"D"," ","m",[453],"27 detectors: regex rules, entropy strings, keyword names",[455],"TOML rule set, regex plus entropy, extended rule by rule",[457],"Over 800 classified credential types",[459,461,463,465],[460,408,404,405,421,405,411,417,403,405,423,428],"V",[462],"Yes, a network call per recognised pattern",[464],"No",[466],"Yes, it logs in to check whether the credential is live",[468,470,472,474],[469,431,417,403,450,405,403,450,404,408,417,410,413],"W",[471],"Git-tracked files in the worktree, plus the library API",[473],"Git patches through git log -p, directories, stdin",[475],"Git, GitHub, GitLab, S3, GCS, Docker, Jenkins, Elasticsearch and more",[477,480,482,484],[478,428,423,479,428,450,413,403,417,403,408],"K","w",[481],"Accepted findings: a committed, audited baseline",[483],"Findings from a report file used as a baseline path",[485],"Result filtering, no baseline concept",{"type":116,"content":487},[488],"The comparison that matters is where the effort goes. gitleaks is one Go binary with an excellent TOML rule format, faster to adopt, and its author now states plainly that the project is feature complete with security patches only and that new work has moved to a different project. TruffleHog goes the other way: it verifies credentials against live APIs, which is the only way to be sure a finding is urgent, and it pays for that with 800-odd credential types and an AGPL-3.0 licence that some legal departments will not sign. detect-secrets trades breadth for the one workflow the others lack: an audited, committed list of what is already known, and a migration off it.",{"type":129,"level":130,"id":109,"text":110},{"type":116,"content":491},[492],"Adopt it, but as infrastructure rather than as a project. The baseline model is the correct answer for a repository with years of history and no budget for a clean-up sprint, and it produces the artefact a security review actually asks for: a list of credentials to rotate. It is not the tool to reach for in a greenfield repository, where gitleaks is simpler, or for a team that needs to know whether a leaked key still works, which is TruffleHog's job.",{"type":148,"ordered":306,"items":494},[495,497,499,501,503],[496],"Choose it when the repository already holds secrets, the history cannot be rewritten, and the goal is to stop the bleeding without a migration project.",[498],"Keep the baseline in the repository and make its diff part of the review. A baseline that changes in an unexplained commit is the failure mode to watch for.",[500],"Budget a day for tuning. The tool is exactly as good as its labelled baseline, and the labelling is manual.",[502],"Pair it with server-side scanning rather than replacing it. detect-secrets blocks on a developer's machine; something still has to scan what already landed.",[504],"Do not build new automation on the assumption that the detector set will grow. Pin 1.5.0, read master if you need Python 3.13, and budget for a successor if the project stays quiet.",{"type":287,"variant":506,"title":507,"body":508},"note","One rule of thumb",[509],[510],"If nobody on the team is willing to rotate the keys the baseline lists, running detect-secrets buys nothing. It reduces the number of future incidents; it does not reduce the ones already in the repository.",{"type":129,"level":130,"id":112,"text":113},{"type":148,"ordered":306,"items":513},[514,517,520,523,526,529,532,535,538],[515],{"tag":417,"href":32,"children":516},[31],[518],{"tag":417,"href":35,"children":519},[34],[521],{"tag":417,"href":38,"children":522},[37],[524],{"tag":417,"href":41,"children":525},[40],[527],{"tag":417,"href":44,"children":528},[43],[530],{"tag":417,"href":47,"children":531},[46],[533],{"tag":417,"href":50,"children":534},[49],[536],{"tag":417,"href":53,"children":537},[52],[539],{"tag":417,"href":56,"children":540},[55],[542,601,657,714],{"slug":543,"published":544,"minutes":6,"category":7,"tags":545,"keywords":550,"about":558,"sources":566,"cover":594,"og":595,"expertise":59,"locales":596,"lang":61,"title":597,"description":598,"coverAlt":599,"url":600,"pricing":67,"kind":547},"guardrails-ai","2026-09-29",[546,547,548,549],"Guardrails","Output validation","LLM reliability","Python",[551,552,553,554,555,556,557],"guardrails ai","guardrails ai validators","llm output validation python","guardrails vs nemo guardrails","guardrails on_fail actions","llm guardrails framework","pii validation llm output",[559,562,563],{"name":560,"url":561},"NVIDIA","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FNVIDIA",{"name":27,"url":28},{"name":564,"url":565},"Large language model","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FLarge_language_model",[567,570,573,576,579,582,585,588,591],{"title":568,"url":569},"Guardrails AI on GitHub: README, news and FAQ","https:\u002F\u002Fgithub.com\u002Fguardrails-ai\u002Fguardrails",{"title":571,"url":572},"guardrails-ai 0.11.0 on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Fguardrails-ai\u002F",{"title":574,"url":575},"Guardrails Hub: 65 validators","https:\u002F\u002Fwww.guardrailsai.com\u002Fhub",{"title":577,"url":578},"Guardrails documentation: error remediation and on-fail actions","https:\u002F\u002Fwww.guardrailsai.com\u002Fdocs\u002Fconcepts\u002Ferror_remediation",{"title":580,"url":581},"Guardrails documentation: use on-fail actions","https:\u002F\u002Fwww.guardrailsai.com\u002Fguardrails\u002Fdocs\u002Fhow-to-guides\u002Fuse_on_fail_actions",{"title":583,"url":584},"Migration issue 1560: moving off hosted remote inferencing","https:\u002F\u002Fgithub.com\u002Fguardrails-ai\u002Fguardrails\u002Fissues\u002F1560",{"title":586,"url":587},"NVIDIA NeMo Guardrails on GitHub","https:\u002F\u002Fgithub.com\u002FNVIDIA-NeMo\u002FGuardrails",{"title":589,"url":590},"NVIDIA NeMo Guardrails documentation","https:\u002F\u002Fdocs.nvidia.com\u002Fnemo\u002Fguardrails\u002Flatest\u002Findex.html",{"title":592,"url":593},"OpenAI API pricing, including moderation","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fpricing","\u002Fimages\u002Fblog\u002Fguardrails-ai\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fguardrails-ai\u002Fog.jpg",[61,62,63],"Guardrails AI: validating what the model returns","A review of Guardrails AI: 65 hub validators, eight on-fail actions, the August 2026 shutdown of hosted inferencing, and when NeMo Guardrails fits better.","Guardrails AI cover artwork with validator pipeline labels","https:\u002F\u002Fwww.guardrailsai.com",{"slug":602,"published":603,"minutes":6,"category":7,"tags":604,"keywords":610,"about":617,"sources":624,"cover":649,"og":650,"expertise":59,"locales":651,"lang":61,"title":652,"description":653,"coverAlt":654,"url":620,"pricing":655,"kind":656},"semgrep","2026-08-14",[605,606,607,608,609],"SAST","Static analysis","CI security","Rule authoring","AppSec",[602,611,612,613,614,615,616],"semgrep vs codeql","semgrep rules","semgrep pricing","semgrep pro engine","free sast tools","semgrep ci github actions",[618,621],{"name":619,"url":620},"Semgrep","https:\u002F\u002Fsemgrep.dev",{"name":622,"url":623},"Static application security testing","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FStatic_application_security_testing",[625,628,631,634,637,640,643,646],{"title":626,"url":627},"Semgrep pricing: Free, Teams and Enterprise","https:\u002F\u002Fsemgrep.dev\u002Fpricing\u002F",{"title":629,"url":630},"Semgrep Community Edition","https:\u002F\u002Fsemgrep.dev\u002Fproducts\u002Fcommunity-edition",{"title":632,"url":633},"Semgrep documentation: cross-file analysis","https:\u002F\u002Fdocs.semgrep.dev\u002Fsemgrep-code\u002Fsemgrep-pro-engine-intro\u002F",{"title":635,"url":636},"Semgrep documentation: usage and billing","https:\u002F\u002Fdocs.semgrep.dev\u002Fusage-and-billing\u002Foverview\u002F",{"title":638,"url":639},"Semgrep releases: v1.179.0","https:\u002F\u002Fgithub.com\u002Fsemgrep\u002Fsemgrep\u002Freleases",{"title":641,"url":642},"Semgrep Rules License v1.0","https:\u002F\u002Fsemgrep.dev\u002Flegal\u002Frules-license\u002F",{"title":644,"url":645},"Important updates to Semgrep OSS, 13 December 2024","https:\u002F\u002Fsemgrep.dev\u002Fblog\u002F2024\u002Fimportant-updates-to-semgrep-oss\u002F",{"title":647,"url":648},"OpenGrep repository","https:\u002F\u002Fgithub.com\u002Fopengrep\u002Fopengrep","\u002Fimages\u002Fblog\u002Fsemgrep\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fsemgrep\u002Fog.jpg",[61,62,63],"Semgrep: static analysis that fits in a pull request","Semgrep parses 30-plus languages and matches YAML patterns in seconds, and the engine is free under LGPL-2.1. Cross-file analysis, the rulesets and the AI triage sit behind paid tiers.","Diagram of the Semgrep scan pipeline, from source files through parsing and rule matching to reported findings","Free · from $30 per seat","Static analysis with AI rules",{"slug":658,"published":659,"minutes":660,"category":7,"tags":661,"keywords":665,"about":674,"sources":680,"cover":705,"og":706,"expertise":59,"locales":707,"lang":61,"title":708,"description":709,"coverAlt":710,"url":711,"pricing":712,"kind":713},"lakera-guard","2026-08-04",9,[662,546,663,664],"Prompt injection","LLM security","Content moderation",[666,667,668,669,670,671,672,673],"lakera guard","lakera guard review","prompt injection filter","prompt injection detection","llm guardrails comparison","pint benchmark","check point ai guardrails","lakera pricing",[675,677],{"name":662,"url":676},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrompt_injection",{"name":678,"url":679},"Check Point","https:\u002F\u002Fwww.checkpoint.com\u002F",[681,684,687,690,693,696,699,702],{"title":682,"url":683},"Lakera documentation: Guard API","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fapi\u002Fguard",{"title":685,"url":686},"Guard API endpoint reference","https:\u002F\u002Fdocs.lakera.ai\u002Fapi-reference\u002Flakera-api\u002Fguard\u002Fscreen-content",{"title":688,"url":689},"Lakera documentation: projects","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fprojects",{"title":691,"url":692},"Lakera documentation: self-hosting","https:\u002F\u002Fdocs.lakera.ai\u002Fdocs\u002Fselfhosting",{"title":694,"url":695},"Lakera platform pricing","https:\u002F\u002Fplatform.lakera.ai\u002Fpricing",{"title":697,"url":698},"PINT benchmark on GitHub","https:\u002F\u002Fgithub.com\u002Flakeraai\u002Fpint-benchmark",{"title":700,"url":701},"Lakera homepage","https:\u002F\u002Fwww.lakera.ai\u002F",{"title":703,"url":704},"Check Point press release on the Lakera acquisition","https:\u002F\u002Fwww.checkpoint.com\u002Fpress-releases\u002Fcheck-point-acquires-lakera-to-deliver-end-to-end-ai-security-for-enterprises\u002F","\u002Fimages\u002Fblog\u002Flakera-guard\u002Fcover.webp","\u002Fimages\u002Fblog\u002Flakera-guard\u002Fog.jpg",[61,62,63],"Lakera Guard: prompt injection filtering at the request boundary","A review of Lakera Guard: one endpoint before the model, the PINT benchmark behind its scores, and why the free tier stops at 10,000 requests a month.","Cover art for the Lakera Guard review: a filter screen in front of a language model","https:\u002F\u002Fwww.lakera.ai","Free tier · from $20 per month","Prompt injection filter",{"slug":715,"published":716,"minutes":660,"category":7,"tags":717,"keywords":719,"about":724,"sources":729,"cover":741,"og":742,"expertise":59,"locales":743,"lang":61,"title":744,"description":745,"coverAlt":746,"url":727,"pricing":67,"kind":747},"rebuff","2026-06-22",[662,663,546,718],"Canary tokens",[715,669,720,721,722,723],"rebuff python sdk","llm prompt injection guardrail","canary token leak detection","rebuff alternative",[725,728],{"name":726,"url":727},"Rebuff","https:\u002F\u002Fgithub.com\u002Fprotectai\u002Frebuff",{"name":564,"url":565},[730,732,735,738],{"title":731,"url":727},"Rebuff repository, archived 16 May 2025",{"title":733,"url":734},"Rebuff 0.1.1 on PyPI, released 20 January 2024","https:\u002F\u002Fpypi.org\u002Fproject\u002Frebuff\u002F",{"title":736,"url":737},"LangChain: Rebuff, detecting prompt injection attacks","https:\u002F\u002Fwww.langchain.com\u002Fblog\u002Frebuff",{"title":739,"url":740},"LLM Guard repository, archived 9 July 2026","https:\u002F\u002Fgithub.com\u002Fprotectai\u002Fllm-guard","\u002Fimages\u002Fblog\u002Frebuff\u002Fcover.webp","\u002Fimages\u002Fblog\u002Frebuff\u002Fog.jpg",[61,62,63],"Rebuff: four layers of prompt injection detection, now archived","Rebuff scored prompts with heuristics, an LLM, a vector store of past attacks and canary tokens. The repository was archived in May 2025 and the last release dates from January 2024.","Diagram of the Rebuff detection path, from incoming prompt through heuristics, LLM check and vector search to a verdict","Prompt injection detection",1791383548842]