areusure
v0.1.1
Published
An intelligent pre-commit hook that catches secrets before they enter git history
Readme
areusure
An intelligent pre-commit hook that catches secrets before they enter git history.
What it detects
- Known patterns — AWS keys, GitHub tokens, Slack tokens, Google API keys, private keys, generic API keys/secrets/passwords
- Dangerous files —
.env,id_rsa,id_ed25519,credentials.json,.htpasswd,*.pem,*.key,*.p12,*.pfx,*.keystore - High entropy strings — catches random-looking strings that might be secrets (Shannon entropy analysis)
Install
npm install -g areusureSetup
Run this inside any git repo to install the pre-commit hook:
areusure initThat's it. Every git commit will now be scanned for secrets automatically.
Usage
# Scan staged changes manually
areusure
# CI/CD mode — outputs JSON
areusure --ciExample output
🚨 areusure found potential secrets:
⚠️ [AWS Access Key] in src/config.js:Line 12
+const key = "AKIA1234567890ABCDEF"
Commit aborted. Fix the issues above or use git commit --no-verify to skip.CI/CD JSON output
{
"ok": false,
"issues": [
{
"type": "secret",
"file": "src/config.js",
"line": 12,
"patterns": ["AWS Access Key"]
}
]
}Whitelisting false positives
Create a .imsure file in your project root:
# Lines starting with # are comments
# Whitelist by content (if the flagged line contains this string, skip it)
AKIA_TEST_KEY_NOT_REAL
# Whitelist by file path
test/fixtures/dummy.pemBypass
If you're sure a commit is safe, you can skip the hook:
git commit --no-verifyLicense
MIT
