4 ms·
Are there any open source tools that scans the code and detects such gaffes
by connectsnk 11mo ago
Are there any open source tools that scans the code and detects such gaffes
- UltraMagnus 11mo agoNot open source, but I have used this before, and they have a very generous free tier: https://www.gitguardian.com/monitor-internal-repositories-for-secrets https://www.gitguardian.com/monitor-internal-repositories-fo... You install their Github app and give them access to your Github repo (private repos are ok too) and they run a Github workflow when each PR is submitted scanning for secrets that should not be in the code. Really happy with how their product works.
- unsungNovelty 11mo agoIf you weren't aware of it... There is a world of static application security tools (SAST) which can help you. Add them to your text editor/ci/cd to use them. https://owasp.org/www-community/Source_Code_Analysis_Tools https://owasp.org/www-community/Source_Code_Analysis_Tools
- vivzkestrel 11mo agostupid question, can we not make a regex for searching API keys for particular APIs and do a brute force scan across the internet
- richbell 11mo agoThere are a number of products and open source tools that do this. Look up "secret scanning".
- EatonZ 11mo agoTruffleHog: https://trufflesecurity.com/trufflehog https://trufflesecurity.com/trufflehog I worked for them a little bit and their product is really impressive and works great.
- heretoread9000 11mo agotrufflehog is a good starting point, then bake in your own simple regex into your github actions or equivalent and make it part of your test suite