secretfence
v0.1.0
Published
Stop secrets before they ever leave your machine. A fast, local-first, developer-friendly secret scanner and pre-push guard for Git repositories.
Maintainers
Readme
SecretFence
Stop secrets before they ever leave your machine.
SecretFence is a fast, local-first CLI that catches hardcoded API keys, passwords, and credentials before they get pushed to GitHub, GitLab, Bitbucket, or Azure DevOps — built for the developer experience of JavaScript/TypeScript teams, with 41 built-in detectors, real multi-core scanning, and zero cloud dependency.
✓ 650 files scanned
Found
🔴 High 2 🟠 Medium 4 🟡 Low 1
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔴 High AWS Secret Access Key
File src/config/aws.ts:28:12
Risk Anyone with this key may access your AWS account.
Fix Move to .env and rotate the key immediately.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Push Blocked Why SecretFence
- Fast — scans 10,000 files in ~1.2 seconds on a single core using a worker-thread pool; scales with available CPU cores.
- Private — everything runs locally. No account, no cloud upload, no
telemetry. The only network calls are an optional version check
(
secretfence update) and an opt-in live-credential-validation flag (--validate), both off unless you ask for them. - Low false positives — regex + entropy scoring, plus automatic suppression for test/fixture/doc files and placeholder values, means fewer "cry wolf" findings than a bare-regex scanner.
- Actionable output — every finding includes exactly what to do about it: which key, where, how confident, and the specific rotation step.
- Extensible — add detectors via config (
customRules), or publish asecretfence-plugin-*package. Adding a detector never requires touching scanner internals.
Quick start
npm install -g secretfence
cd your-repo
secretfence scan # scan everything
secretfence install # add a pre-push hook that blocks High/Critical secrets
secretfence doctor # verify your setupSee docs/installation.md for dev-dependency and
CI setup, and docs/configuration.md for
.secretfence.json options.
Usage
secretfence scan # scan the whole repo
secretfence scan ./src # scan a folder
secretfence scan ./src/config.ts # scan a single file
secretfence scan --staged # scan files staged for commit
secretfence scan --diff # scan files changed vs HEAD
secretfence scan --commit <sha> # scan a specific commit
secretfence scan --min-severity high # only report high/critical
secretfence scan --format sarif --output results.sarif # for GitHub code scanning
secretfence report --format html # export a standalone HTML report
secretfence ignore "legacy/**" # add a pattern to .secretfenceignore
secretfence config # show the resolved configuration
secretfence benchmark # measure scan throughputEvery command supports --help. The short alias sf works everywhere
secretfence does.
| Command | Purpose |
|---|---|
| scan | Scan for secrets (see modes above) |
| install / uninstall | Manage the pre-push Git hook |
| doctor | Diagnose your setup |
| init | Create a .secretfence.json |
| config | Show the resolved configuration |
| ignore <pattern> | Add a pattern to .secretfenceignore |
| report | Run a scan and export json/markdown/html/sarif |
| update | Check for a newer version |
| version | Print the current version |
| benchmark | Measure scan throughput on synthetic files |
What it catches
41 detectors across cloud (AWS, GCP, Azure, DigitalOcean, Cloudflare), AI
providers (OpenAI, Anthropic, Gemini), payments (Stripe, PayPal,
Razorpay), VCS platforms (GitHub, GitLab, Bitbucket, Azure DevOps),
messaging (Slack, Discord, Twilio, SendGrid), databases (MongoDB,
Postgres, MySQL, Redis, Supabase, Firebase), cryptographic material (RSA/
PEM/OpenSSH/PGP private keys), and generic patterns (JWTs, bearer tokens,
basic auth, OAuth secrets, .env files). Full list with detector IDs:
docs/detectors.md.
CI integration
# .github/workflows/secretfence.yml
- run: npx secretfence scan --min-severity high --format sarif --output results.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarifSecurity
Matched secret values are masked before they ever leave the detection
layer — every output format (terminal, JSON, Markdown, HTML, SARIF) shows
only a masked value like sk-a****************9fd, never the raw
credential. See SECURITY.md for the full policy and how
to report a vulnerability.
Documentation
License
MIT — see LICENSE.
