Back to the marketplace
Developer ToolingVerifiedv1.0.0

Git Secret Guard: Pre-commit Credential Scanner

By iTechVista Studio•No reviews yet•0 purchases

Overview

A zero-dependency git pre-commit hook and Node CLI that refuses commits containing credentials. It recognises 20 key formats by their provider prefix, including Stripe, GitHub, AWS, Supabase, Vercel, OpenAI, Anthropic, Slack, npm, Shopify, SendGrid and PEM private keys, and decodes JWTs so a Supabase service_role key blocks while the browser-safe anon key does not. It also blocks .env files, SSH keys, key stores and recovery-code dumps by file name. Beyond the hook, --all scans every tracked file, --history scans every file version reachable from any ref and names the commit that introduced each finding, and --dir scans build output, optionally failing when a server-only value from your .env file was inlined into the bundle. A JSON config adds custom patterns, allow-lists files or single lines, downgrades rules and blocks known leaked values by SHA-256. The installer never overwrites a hook it did not write. Matching is by shape, so passwords, connection strings and other prefix-less secrets are not detected, and git commit --no-verify bypasses it; the README lists every limit. 65 tests pass on Windows 11 with Node 24 and Git 2.55. macOS, Linux and older Node versions have not been run.

#git#pre-commit#secrets#security#cli

Source preview

  function scanText(p, text) {
    if (isAllowedFile(p)) return [];
    const found = [];
    const lines = text.split(/\r?\n/);
    for (let n = 0; n < lines.length; n++) {
      const line = lines[n];
      if (INLINE_ALLOW.test(line)) continue;
      const lineNo = n + 1;

      for (const rule of patterns) {
        for (const m of line.matchAll(rule.re)) {
          if (rule.validate && !rule.validate(m[0])) continue;
          const block = effective(rule.name, rule.block);
          if (block === null) continue;
          found.push({ path: p, line: lineNo, rule: rule.name, block, sample: redact(m[0]) });
        }
      }

      for (const m of line.matchAll(rules.JWT_RE)) {
        const verdict = classifyJwt(m[0]);
        if (!verdict) continue;
        const block = effective(verdict.rule, verdict.block);
        if (block === null) continue;
        found.push({ path: p, line: lineNo, rule: verdict.rule, block, sample: `${redact(m[0])} ${verdict.detail}` });
      }
Choose a licence
$12.00

Excludes tax, added at checkout where it applies.

DeliveryPrivate download link
Review statusPassed