AppSecNews

Secret Scanning

Secret Scanning

Find credentials, tokens and keys committed to code or exposed in build systems.

9 tools profiled

How it differs Finds credentials committed to code, git history and build artifacts. Vulnerable dependencies are SCA, not this.

License
Subcategory
Deployment
Integrations
Maturity
Signals
Clear

2 tools match

  • git-secrets

    AWS Labs

    Secret Scanning

    Shell-based git hook that refuses commits matching a configured set of credential patterns, with built-in rules for AWS access keys.

    Open source
    Established
  • Gitleaks

    Gitleaks

    Secret Scanning

    Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.

    Open source
    Established
  • git-secrets

    AWS Labs

    Shell-based git hook that refuses commits matching a configured set of credential patterns, with built-in rules for AWS access keys.

    Open source Established
    Secret Scanning
  • Gitleaks

    Gitleaks

    Go command line scanner that walks git history and file trees against a TOML rule set, combining regular expressions with entropy thresholds to find committed secrets.

    Open source Established
    Secret Scanning
Tick up to 4 tools above.