Metadata-Version: 2.4
Name: simple-detect-secrets
Version: 0.0.1
Summary: Tool for detecting secrets in the codebase
Keywords: secret-management,pre-commit,security,entropy-checks
Author: Malthe Jørgensen
Author-email: Malthe Jørgensen <malthe.jorgensen@gmail.com>
License-Expression: Apache-2.0
License-File: LICENSE
License-File: NOTICE
Classifier: Programming Language :: Python :: 3
Classifier: Intended Audience :: Developers
Classifier: Topic :: Software Development
Classifier: Topic :: Utilities
Classifier: Environment :: Console
Classifier: Operating System :: OS Independent
Classifier: Development Status :: 5 - Production/Stable
Requires-Dist: pyyaml
Requires-Dist: requests
Requires-Dist: pyahocorasick ; extra == 'word-list'
Requires-Python: >=3.13
Project-URL: Homepage, https://github.com/malthejorgensen/simple-detect-secrets
Provides-Extra: word-list
Description-Content-Type: text/markdown

simple-detect-secrets
=====================

`simple-detect-secrets` tries to find secrets (passwords, auth tokens) in a code base.


Simply run `uvx simple-detect-secrets`.


Developing
----------

```bash
uv sync --locked
uv run simple-detect-secrets scan
uv run pytest tests
```

Build the source distribution and wheel with `uv build`. Install the optional
word-list support with `uv sync --extra word_list`.

Caveats
-------

This is not meant to be a sure-fire solution to prevent secrets from entering
the codebase. Only proper developer education can truly do that. This pre-commit
hook merely implements several heuristics to try and prevent obvious cases of
committing secrets.

Things that won't be prevented
------------------------------

- Multi-line secrets
- Default passwords that don't trigger the `KeywordDetector` (e.g. `login = "hunter2"`)

Notes
-----

This is an old fork of Yelp's [detect-secrets](https://github.com/Yelp/detect-secrets).

This is a command line tool:

- never calls the network
- doesn't obfuscate/hash the secrets that it finds
- doesn't have plugins
