
Gitleaks
Gitleaks is a free open-source secret scanner used to detect hardcoded passwords, API keys, and tokens in git repos and files for security and dev teams.
0 upvotes · 0 downvotes
No ratings yet
- Category
- Application Security
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 6 October 2026
What it is
A fast command line scanner that searches git history, files, and piped input for strings that look like credentials, using regular expressions and entropy.
What it helps with
- Finding committed secrets across a repository and its full history
- Running as a pre-commit hook or a pipeline step to block leaks
- Tuning detection with custom rules and allowlists
Who it's for
Developers and security teams checking code they own for exposed secrets.
Worth knowing
It is distributed as a single Go binary and is also available through Homebrew and Docker. The project is now considered feature complete and receives security fixes while its author builds a separate successor.
Do I need a license to run its GitHub Action?
Organization repositories need a free license key, while personal repositories need none.
Who maintains it now?
It is maintained under Truffle Security.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.