DEV Community

Repository-Scanner
Repository-Scanner

Posted on

We got your secrets

We got your secrets. Do you want ours?

Source code contains tons of sensitive information, like personable identifiable information in test data, usernames and passwords that someone forgot to parameterize, private keys, personal access tokens etc. You name it, you can find it.

But what if you could scan Github repos, Azure DevOps repos, Bitbucket repos? And if the secrets are neatly organized, easy to triage, sorted and transformed into usable metrics?

Image description

With Repository Scanner (licensed under MIT) you can do it all. Repository Scanner is an Enterprise Grade open source project, running in isolation as a continuous monitoring agent or running in pipelines as a CI stage, which captures secrets and presents the data in an easy to consume manner to Red Teams, Security Consultants, Test teams, Developers, CICD maintenance, Management (metrics) and every other interested stakeholder.

Try it out (again, fully licensed under MIT) via https://github.com/abnamro/repository-scanner and leave a ⭐️ star if you like what you see.

Image of Datadog

The Future of AI, LLMs, and Observability on Google Cloud

Datadog sat down with Google’s Director of AI to discuss the current and future states of AI, ML, and LLMs on Google Cloud. Discover 7 key insights for technical leaders, covering everything from upskilling teams to observability best practices

Learn More

Top comments (0)

A Workflow Copilot. Tailored to You.

Pieces.app image

Our desktop app, with its intelligent copilot, streamlines coding by generating snippets, extracting code from screenshots, and accelerating problem-solving.

Read the docs