Join us

ContentUpdates and recent posts about detect-secrets..
Discovery IconThat's all about @detect-secrets — explore more posts below...
 Activity
@devopslinks added a new tool Syft , 1 hour, 26 minutes ago.
 Activity
@kaptain added a new tool KubeLinter , 1 hour, 30 minutes ago.
 Activity
@bridgecrewio started using tool checkov , 1 hour, 34 minutes ago.
 Activity
@devopslinks added a new tool Grype , 1 hour, 37 minutes ago.
 Activity
@kaptain added a new tool Hadolint , 1 hour, 45 minutes ago.
 Activity
@varbear added a new tool Bandit , 1 hour, 48 minutes ago.
 Activity
@devopslinks added a new tool JFrog Xray , 1 hour, 51 minutes ago.
 Activity
@devopslinks added a new tool OWASP Dependency-Check , 1 hour, 55 minutes ago.
 Activity
@varbear added a new tool pre-commit , 1 hour, 59 minutes ago.
 Activity
@devopslinks added a new tool GitGuardian , 2 hours, 3 minutes ago.
Detect Secrets, created by Yelp Engineering, is a Python-based secret scanner designed for large, complex codebases. It uses a plugin architecture to detect high-risk secrets such as API keys, tokens, passwords, and certificates. The tool focuses on false-positive reduction by hashing baseline fingerprints, allowing teams to track only new or changed exposures over time. It integrates with CI pipelines, pre-commit hooks, and enterprise security workflows. Its extensible design and strong baseline mechanism make it popular in large engineering organizations that need scalable, low-noise secret detection.