<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Devansh Shukla</title>
    <description>The latest articles on DEV Community by Devansh Shukla (@devansh_shukla).</description>
    <link>https://dev.to/devansh_shukla</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4162651%2F0fc82d85-af06-44d9-9dca-45c05d546dbf.jpeg</url>
      <title>DEV Community: Devansh Shukla</title>
      <link>https://dev.to/devansh_shukla</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/devansh_shukla"/>
    <language>en</language>
    <item>
      <title>🔐 RepoShield AI — Local-First Secret Exposure Detection with Gitleaks + Gemma</title>
      <dc:creator>Devansh Shukla</dc:creator>
      <pubDate>Mon, 05 Oct 2026 06:16:20 +0000</pubDate>
      <link>https://dev.to/devansh_shukla/reposhield-ai-local-first-secret-exposure-detection-with-gitleaks-gemma-4jo4</link>
      <guid>https://dev.to/devansh_shukla/reposhield-ai-local-first-secret-exposure-detection-with-gitleaks-gemma-4jo4</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a submission for the &lt;a href="https://dev.to/challenges/hacktoberfest-weekend-2026-10-01"&gt;Hacktoberfest Weekend Challenge: Build for a Friend&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Built
&lt;/h2&gt;

&lt;p&gt;I built RepoShield AI, a local-first security tool that helps developers identify and understand potential secret exposure in their repositories.&lt;/p&gt;

&lt;p&gt;I built it for a developer friend who wanted a simpler way to investigate accidentally exposed credentials without sending sensitive repository information to a cloud AI service.&lt;/p&gt;

&lt;p&gt;The core idea is simple:&lt;br&gt;
   Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.&lt;/p&gt;

&lt;p&gt;RepoShield combines:&lt;/p&gt;

&lt;p&gt;🔐 Gitleaks for deterministic secret detection&lt;br&gt;
🛡️ A sanitization layer that withholds raw secrets and absolute paths&lt;br&gt;
🤖 Ollama + Gemma 3 1B for local AI-assisted analysis&lt;br&gt;
📊 A React + TypeScript security dashboard&lt;br&gt;
📄 Sanitized JSON and Markdown reports&lt;/p&gt;

&lt;p&gt;The AI model is not responsible for detecting the secret.&lt;br&gt;
Instead:&lt;br&gt;
Repository&lt;br&gt;
    ↓&lt;br&gt;
Gitleaks&lt;br&gt;
    ↓&lt;br&gt;
Finding&lt;br&gt;
    ↓&lt;br&gt;
Secure Sanitization&lt;br&gt;
    ↓&lt;br&gt;
Safe Metadata&lt;br&gt;
    ↓&lt;br&gt;
Ollama + Gemma 3 1B&lt;br&gt;
    ↓&lt;br&gt;
Risk Explanation + Remediation.&lt;/p&gt;

&lt;p&gt;This separation was one of the most important security decisions in the project.&lt;/p&gt;
&lt;h2&gt;
  
  
  Demo
&lt;/h2&gt;

&lt;p&gt;The project has been validated as a local application with a real end-to-end workflow.&lt;/p&gt;

&lt;p&gt;The validated demo performs:&lt;br&gt;
&lt;/p&gt;
&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
      &lt;div class="c-embed__body flex items-center justify-between"&gt;
        &lt;a href="https://drive.google.com/drive/folders/1tVL23rCyomOP_FQ-Exdkz50MXgqtYBjX?usp=sharing" rel="noopener noreferrer" class="c-link fw-bold flex items-center"&gt;
          &lt;span class="mr-2"&gt;drive.google.com&lt;/span&gt;
          

        &lt;/a&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;Gitleaks detection&lt;br&gt;
Authorized local repository scanning&lt;br&gt;
Secret/path sanitization&lt;br&gt;
Finding investigation&lt;br&gt;
Local Gemma analysis&lt;br&gt;
Risk explanation&lt;br&gt;
Remediation guidance&lt;br&gt;
Sanitized report generation.&lt;/p&gt;
&lt;h2&gt;
  
  
  Code
&lt;/h2&gt;

&lt;p&gt;The complete project is open source:&lt;/p&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/devanshshukla-3004" rel="noopener noreferrer"&gt;
        devanshshukla-3004
      &lt;/a&gt; / &lt;a href="https://github.com/devanshshukla-3004/RepoShield-AI" rel="noopener noreferrer"&gt;
        RepoShield-AI
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      Local-first secret exposure review with Gitleaks detection, secure finding sanitization, and optional Ollama/Gemma AI triage.
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;RepoShield AI&lt;/h1&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Local-first secret exposure review for repositories — deterministic detection, privacy-preserving triage, and optional local AI assistance.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/devanshshukla-3004/RepoShield-AI/actions/workflows/checks.yml" rel="noopener noreferrer"&gt;&lt;img src="https://github.com/devanshshukla-3004/RepoShield-AI/actions/workflows/checks.yml/badge.svg" alt="CI"&gt;&lt;/a&gt;
&lt;a href="https://nodejs.org/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/07971eee1adf215c065c8e74471761f691c4d5b8485868a0ed2f275c1728d89e/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4e6f64652e6a732d32342d3333393933333f6c6f676f3d6e6f64652e6a73266c6f676f436f6c6f723d7768697465" alt="Node.js"&gt;&lt;/a&gt;
&lt;a href="https://www.typescriptlang.org/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/eeb868d33b93b31e4ae18fab8c55f182c7491e9560217a79ef1c8f5489330cc1/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f547970655363726970742d352e782d3331373843363f6c6f676f3d74797065736372697074266c6f676f436f6c6f723d7768697465" alt="TypeScript"&gt;&lt;/a&gt;
&lt;a href="https://react.dev/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/e888ee0a66683b2ec3b9061b52fad4d8b7397e8a13c2a9ae866a37acabad541d/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f52656163742d31382d3631444146423f6c6f676f3d7265616374266c6f676f436f6c6f723d313131" alt="React"&gt;&lt;/a&gt;
&lt;a href="https://github.com/gitleaks/gitleaks" rel="noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/9978f8eba987d61a2d678547e02639e1b7f224a079391f053ee9fc042bcf9adb/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f446574656374696f6e2d4769746c65616b732d313131383237" alt="Gitleaks"&gt;&lt;/a&gt;
&lt;a href="https://ollama.com/" rel="nofollow noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/c174fbc07d24c98aa0a7e164edbecd71947768bf2716ef509e9d2465526a3a04/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f41492d4f6c6c616d612d313131383237" alt="Ollama"&gt;&lt;/a&gt;
&lt;a href="https://github.com/devanshshukla-3004/RepoShield-AI/LICENSE" rel="noopener noreferrer"&gt;&lt;img src="https://camo.githubusercontent.com/6c290d3fa30f4a51454757590f2beec29a83cccdfcd9945e2c0d387af01477f3/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f4c6963656e73652d4d49542d323263353565" alt="License"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;RepoShield AI helps developers review repositories for potential secret exposure &lt;strong&gt;before code is shared&lt;/strong&gt;. It combines deterministic &lt;a href="https://github.com/gitleaks/gitleaks" rel="noopener noreferrer"&gt;Gitleaks&lt;/a&gt; detection with a deliberately narrow privacy boundary and optional local &lt;a href="https://ollama.com/" rel="nofollow noopener noreferrer"&gt;Ollama&lt;/a&gt; / &lt;code&gt;gemma3:1b&lt;/code&gt; analysis.&lt;/p&gt;
&lt;p&gt;The core design principle is simple:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;Why RepoShield?&lt;/h2&gt;
&lt;/div&gt;
&lt;p&gt;Secret scanners are good at finding patterns. Developers still need to understand what a finding means, how serious it may be, and what to do next.&lt;/p&gt;
&lt;p&gt;RepoShield separates those responsibilities:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Gitleaks detects&lt;/strong&gt; potential secrets.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;RepoShield sanitizes&lt;/strong&gt; the result before it reaches the UI or report layer.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Gemma can explain&lt;/strong&gt; the finding locally using only server-defined metadata.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The developer triages and remediates&lt;/strong&gt; the exposure.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This keeps AI in an advisory role rather than allowing a language model…&lt;/p&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/devanshshukla-3004/RepoShield-AI" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;The repository contains the React frontend, Express API, security scanning logic, sanitization layer, AI integration, tests, CI configuration, architecture documentation, and demo media.&lt;/p&gt;

&lt;h2&gt;
  
  
  How I Built It
&lt;/h2&gt;

&lt;p&gt;The project is built around Gemma 3 1B, running locally through Ollama.&lt;/p&gt;

&lt;p&gt;The architecture uses:&lt;/p&gt;

&lt;p&gt;React&lt;br&gt;
TypeScript&lt;br&gt;
Vite&lt;br&gt;
Tailwind CSS&lt;br&gt;
Express&lt;br&gt;
Zod&lt;br&gt;
Gitleaks&lt;br&gt;
Ollama&lt;br&gt;
Gemma 3 1B&lt;br&gt;
GitHub Actions&lt;/p&gt;

&lt;p&gt;The security pipeline intentionally separates detection from AI analysis.&lt;/p&gt;

&lt;p&gt;Gitleaks detects potential secrets first. RepoShield then sanitizes the resulting finding before anything reaches the model.&lt;/p&gt;

&lt;p&gt;The AI layer receives only controlled finding metadata needed to generate an explanation and remediation guidance.&lt;/p&gt;

&lt;p&gt;It does not receive:&lt;/p&gt;

&lt;p&gt;❌ Raw secret values&lt;br&gt;
❌ Source code&lt;br&gt;
❌ Absolute filesystem paths&lt;br&gt;
❌ Raw scanner evidence&lt;/p&gt;

&lt;p&gt;I also added automated tests around path safety and finding sanitization to make the security boundary testable rather than relying only on documentation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Does Open Innovation Matter?
&lt;/h2&gt;

&lt;p&gt;Open innovation made it possible to build the AI portion of this project around a local, open-weight model rather than requiring a closed cloud AI API.&lt;/p&gt;

&lt;p&gt;That matters particularly for cybersecurity.&lt;/p&gt;

&lt;p&gt;Security findings can contain sensitive information. Sending those findings to a third-party API creates another trust boundary.&lt;/p&gt;

&lt;p&gt;With Ollama and Gemma, I could experiment with a local inference workflow where the AI analysis happens on the developer's machine.&lt;/p&gt;

&lt;p&gt;More importantly, open models allowed me to design the system around the question:&lt;br&gt;
    What should the AI never receive?&lt;/p&gt;

&lt;p&gt;Instead of simply sending scanner output to an LLM, I could build a privacy boundary between the security scanner and the model.&lt;/p&gt;

&lt;p&gt;That made local AI a practical part of the security architecture rather than just a chatbot feature.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Agent Session
&lt;/h2&gt;

&lt;p&gt;I used AI-assisted development throughout the project, particularly for architecture exploration, debugging, testing, documentation, and implementation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Prize Categories
&lt;/h2&gt;

&lt;p&gt;Open-source AI / Local AI&lt;/p&gt;

&lt;p&gt;Gemma 3 1B&lt;br&gt;
Ollama&lt;br&gt;
Local inference&lt;/p&gt;

&lt;p&gt;Cybersecurity / Developer Tooling&lt;/p&gt;

&lt;p&gt;Gitleaks&lt;br&gt;
Secure finding sanitization&lt;br&gt;
Repository security analysis&lt;/p&gt;

</description>
      <category>devchallenge</category>
      <category>weekendchallenge</category>
      <category>hf26challenge</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>New To Community</title>
      <dc:creator>Devansh Shukla</dc:creator>
      <pubDate>Mon, 05 Oct 2026 02:17:43 +0000</pubDate>
      <link>https://dev.to/devansh_shukla/new-to-community-5aji</link>
      <guid>https://dev.to/devansh_shukla/new-to-community-5aji</guid>
      <description>&lt;p&gt;Hello Everyone!!! &lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
