From PyPi
$ pip install deepsecrets
From Github via pip
$ pip install git+https://github.com/ntoskernel/deepsecrets.git
$ deepsecrets --target-dir /path/to/your/code --outformat dojo-sarif --outfile report.json
This will run a scan against /path/to/your/code using the default configuration:
Regex using the built-in ruleset
Semantic checks (variable detection, entropy checks)
A report in SARIF format (compatible with DefectDojo and GitHub Security) will be saved to report.json.
The --help command is always ready to guide you, but here are the key flags you can use to tailor the scan to your environment:
--regex-rules /path/to/rules.json: Supply your own custom regex ruleset.
--hashed-values /path/to/hashes.json: Provide a list of pre-hashed known production secrets to search for them securely.
--excluded-paths /path/to/exclusions.json: Override or extend the default paths ignored during scanning.
--disable-masking: Keep potential secrets unmasked in the output report (see caution below)*.
eq. .github/workflows/deepsecrets.yml
Contents
name: DeepSecrets Scan
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install DeepSecrets
run: pip install deepsecrets
- name: Run Scan
run: deepsecrets --target-dir . --outformat dojo-sarif --outfile report.sarif
continue-on-error: true
- name: Upload SARIF report
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: report.sarif