Skip to content

Secrets scan ​

Scans tracked files for credential shapes that are unambiguous enough to act on. One of only two gates that report at error severity.

Gate ID
secrets_scan
Severity
error
Scope
Tracked files (git ls-files)
Tags
securitygit-hygiene

What it checks ​

Scans every git-tracked file for AWS/GitHub/OpenAI/Anthropic/Google/Slack/Stripe API keys, JWTs, private-key headers, and tracked .env files. Honours .gitignore via git ls-files.

Detected patterns ​

PatternShape
AWS access key IDAKIA + 16 upper-case alphanumerics
GitHub PAT (classic)ghp_ / ghs_ / gho_ / ghr_ / ghu_ + 36 chars
GitHub PAT (fine-grained)github_pat_ + 82 chars
OpenAI API keysk- + 48 alphanumerics
Anthropic API keysk-ant- + 40 or more chars
Google API keyAIza + 35 chars
Slack tokenxox[abprs]- + the full numeric-segment shape
Stripe live secret keysk_live_ + 24 or more chars
JWTthree base64url segments, the first two starting eyJ
Private keya -----BEGIN … PRIVATE KEY----- header

Every pattern except the private-key header also requires a Shannon entropy of at least 3.5 over the match. That is what separates a real key from AKIAIOSFODNN7EXAMPLE-style filler in documentation.

A classic GitHub token (ghp_, gho_, ghu_, ghs_, ghr_) also carries a checksum: its last six characters are the CRC-32 of the thirty before them, written in base 62 (0-9A-Za-z). A string that fails it cannot have been issued by GitHub, so it is a typed example, and is reported at info instead of error. It is downgraded, never dropped, so a wrong assumption costs a hidden-by-default entry rather than a missed leak. A token that verifies, any fine-grained github_pat_… token and every other shape are reported exactly as before. The token must be the whole alphanumeric run: a longer one is not the format that carries this checksum and stays an error. Every match on a line is judged (the first 64) and the worst one wins, so an example in front of a real token does not hide it; the history gate judges the same way, an example there being info instead of a warning.

A tracked .env file is reported on its own, regardless of contents.

Scope ​

The gate enumerates files with git ls-files, so anything already ignored is never read. Files above 2 MiB and detected binaries are skipped. Test fixtures and data files are skipped by default: see Configuration.

A finding is not proof

The entropy floor cuts most filler, but the only thing the gate can prove is that a string has the shape of a credential. Verify before you rotate, and if it is real, remember that removing it from the working tree does not remove it from history. See secrets_scan_history.

What a finding says ​

text
.env is tracked in git. .env files typically hold secrets and shouldn't be committed. Move secrets to a vault and add .env to .gitignore.

Turning it off ​

Silence the gate for the whole project in .l0git.json:

json
{
  "ignore": ["secrets_scan"]
}

Or keep it running at a lower severity:

json
{
  "severity": { "secrets_scan": "info" }
}

See also ​

Released under the MIT License. · Privacy & legal