NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1339 most downloaded on PyPI
Tool for detecting secrets in the codebase
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 1.6 years
Nearly every release is documented
notes for 35 of 38 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
38 releases · first in 2018
We're adding support for Python 3.10, 3.11 and 3.12 and we dropped support for Python 3.6 and 3.7! We hope this won't be too disruptive for you all. B
We apologise for the extreme delay in publishing a new release for our beloved detect-secrets. We at Yelp appreciate your continued support and your contributions to this valuable project!
.secrets.baseline is not found. (#719)NotImplementedError in StatisticsAggregator (#678)IndexError in is_prefixed_with_dollar_sign caused by passing empty strings (#712)One column per quarter.
We're dropping support for Python 3.6 starting v1.5.0! Python 3.6 reached EOL on December 23, 2021 and, therefore, is currently unsupported. We hope t
Add Windows operating system to Github CI Action ([ #528 ])
detect-secrets-hook to return output as json ([#569])detect-secrets-hook to return output as json (#569)npm plugin (#551)audit crashing when secret is not found on specified line (#568)# pragma: allowlist nextline secret secrets not filtered out of result set (#575)is_verified flag not stored in PotentialSecret (#578)is_likely_id_string heuristic filter more strict to avoid eliminating true positives (#526)py.typed to enable type hints for package consumers (#579)Continuous integration github action added ([ #506 ])
AttributeError: 'PotentialSecret' object has no attribute 'line_number' by safely falling back to 0 if line_number isn't present. (#476)(#472)Version 1.1 adds some long awaited features to detect-secrets . Here are some highlights:
Version 1.1 adds some long awaited features to detect-secrets. Here are some highlights:
gibberish-detector support, to only flag secrets that "look" like secrets.KeywordDetector became a whole lot more powerful, to catch more keywords, in more permutations.KeywordDetector supports whitespace secrets (#414)KeywordDetector now supports prefix/suffixed keywords, and accuracy updatesaudit --report to extract secret values with a baseline
(#387, thanks [@pablosantiagolopez], @syn-4ck)KeywordDetector now defaults to requiring quotes around secrets (#448)KeywordDetector now searches for more keywords (#430)Settings objects (#444)exclude to exclude-files rather than exclude-lines
(#446)Bump version: 1.0.2 → 1.0.3
Bump version: 1.0.2 → 1.0.3
SecretsCollection subtraction method, to handle non-overlapping files.Bump version: 1.0.1 → 1.0.2
Bump version: 1.0.1 → 1.0.2
KeywordDetector is no longer case-sensitive.Bump version: 1.0.0 → 1.0.1
Bump version: '0.14.3' → 1.0.0
Bump version: '0.14.3' → 1.0.0
Settings object for repeatable, serializable,
configurationsHonestly, too many to list out. Check out the original pull request
(#355) for more details. It's safe to assume
that if you interacted with detect-secrets as a module (rather than solely a pre-commit hook
or CLI tool), the APIs have changed (for the better).
However, with the new upgrade infrastructure in place, the baseline files will auto upgrade by themselves. Users that have used it solely as a pre-commit hook or CLI tool may need to consult the "User Facing Changes" for flag renaming.
NpmDetector (#347, thanks @ninoseki)AzureStorageKeyDetector (#359, thanks @DariuszPorowski)SquareOauthDetector (#398, thanks @pablosantiagolopez)--only-allowlisted flag to scan for inline ignores--list-all-plugins to show a list of all plugins available to the engine--exclude-secrets flag to ignore secrets that match specific regexes
(#391, thanks @pablosantiagolopez)--slim flag to generate baselines that minimize git diffs--disable-filter to disable specific filters--disable-plugin to disable specific plugins# pragma: allowlist nextline secret to ignore the following line
(#367, thanks @nickiaconis)Verify Slack secrets more accurately ([#325], thanks [@dryoni])
Fixed an AttributeError exception in the pre-commit hook, when on Windows ([#321], thanks [@JohnNeville])
AttributeError exception in the pre-commit hook, when on Windows (#321, thanks @JohnNeville)Add missing tuple() conversion that raised a TypeError when using scan --update ([#317], thanks [@shaikmanu797])
tuple() conversion that raised a TypeError when using scan --update (#317, thanks @shaikmanu797)Remove support for Python 2 ([#292], big thanks to [@KevinHock]!)
detect-secrets version (#293, #269)Adding plugin for IBM's Cloudant ([#261], thanks [@killuazhu])
DETECT_SECRETS_SECURITY_TEAM environment variable to customize
the pre-commit hook error message (#283, thanks [@0atman])HighEntropyString scanning supports multiple words (#287)Rationale for the minor version bump:
id in them in the high-entropy plugins (#245)Added a JwtTokenDetector plugin ([#239], thanks [@gdemarcsek])
JwtTokenDetector plugin (#239, thanks [@gdemarcsek])--word-list option for filtering secrets with words in them (#241, do pip install detect-secrets[word_list] to use this feature)Added a MailchimpDetector plugin ([#217], thanks [@dgzlopes])
MailchimpDetector plugin (#217, thanks [@dgzlopes])KeywordDetector plugin (#229)audit functionality where we crashed when the highlighter failed (#228)audit functionality where there was no (b)ack audit functionality when a secret was not found (#215, thanks [@dgzlopes])Added webhook detection to our SlackDetector plugin ([#195], thanks [@adrianbn])
SlackDetector plugin (#195, thanks [@adrianbn])audit --display-results feature to aid plugin development (#205)whitelist/blacklist have been replaced with allowlist/denylist ([#178], thanks [@richo]). This includes using # pragma: allowlist secret now for inlin
whitelist/blacklist have been replaced with allowlist/denylist (#178, thanks [@richo]).
This includes using # pragma: allowlist secret now for inline allowlisting.
# pragma: whitelist secret compatibility will be removed in a later major version bump.StripeDetector plugin (#169, thanks [@dgzlopes])Added an ArtifactoryDetector plugin ([#157] and [#163], thanks [@justineyster])
ArtifactoryDetector plugin (#157 and #163, thanks [@justineyster])KeywordDetector plugin (#162, thanks [@baboateng])configparser import (#155, thanks [@Namburgesas])KeywordDetector plugin, and the maintainability of the corresponding test (#160 and #161, thanks [@baboateng])Fixed a bug where the improved performance for high-entropy strings ([#144]) did not work on Python 2 ([#147])
Added a --keyword-exclude argument to scan ([#132], thanks [@hpandeycodeit])
--keyword-exclude argument to scan (#132, thanks [@hpandeycodeit])KeywordDetector plugin: made quotes required for secrets in .cls and .java files, and skipped {{secrets like this}} in YAML files (#133/#145)UnicodeEncodeError exception in our ini file parser, when using Python 2 (#143)Added a SlackDetector plugin ([#122], thanks [@killuazhu])
SlackDetector plugin (#122, thanks [@killuazhu])--use-all-plugins argument to --update that adds all plugins to the baseline (#124, thanks [@killuazhu])--exclude-files and --exclude-lines arguments to scan (#127)--exclude CLI scan argument (#127)!$&\';) in the BasicAuthDetector regex (#126, #123, thanks [@killuazhu])FALSE_POSITIVES dict for the KeywordDetector plugin, including password (#118)--update was adding all plugins to the baseline, instead of respecting the plugins used in the baseline (#124, thanks [@killuazhu])UnicodeEncodeError exception when scanning non-ini files (e.g. markdown) containing unicode, when using Python 2 (#128, thanks [@killuazhu])UnicodeEncodeError exception in the audit functionality, when using Python 2 (#129, thanks [@killuazhu])audit functionality (#120, thanks [@killuazhu])scan_diff, called by detect-secrets-server, was ignoring inline pragma: whitelist secret comments (#127)pragma: whitelist secret comment (#125, thanks [@killuazhu]]tox.ini testing (#114, thanks [@cclauss])Fixed a TypeError bug introduced in [#111] ([#116])
Fixed a bug where we were adding an extra-newline in detect-secrets scan output ([#111])
Added `null` to the `FALSE_POSITIVES` tuple for the `KeywordDetector` plugin, so we don't alert off of it
Turned the KeywordDetector plugin back on, with new regexes and accuracy improvements ([#86])
KeywordDetector plugin back on, with new regexes and accuracy improvements (#86)AWSAccessKeyDetector plugin (#100).ini types files that don't have a header (#106)PrivateKeyDetector plugin (#104)BasicAuthDetector plugin regex (#98)audit functionality (#98)RegexBasedDetector (#103)BashColor singleton into the colorize function (#109)BasePlugin to use the WHITELIST_REGEX (#99)unidiff from standard dependencies (#101)Made the pre-commit hook automatically update the baseline ([#96])
Added a "Please git add the baseline" message ([#89])
Disabled KeywordDetector plugin temporarily ([#89])
KeywordDetector plugin temporarily (#89)audit functionality, one for small files and the other case-sensitivity in the KeywordDetector plugin (#83, thanks [@jkozera])Added a KeywordDetector plugin, that was horrible and regretful ([#76])
KeywordDetector plugin, that was horrible and regretful (#76)scan --update where we would append the baseline exclude regex to itself (#78)BasicAuthDetector plugin so that it didn't run forever (#80)scan output (#78)Added a (b)ack option to 'Is this a valid secret?' ([#72], thanks [@cleborys])
BasicAuthDetector plugin (#74)Fixed a bug where we didn't skip sequential strings when we should have ([#67])
Scan --all-files option ([#57])
Fixed numbering system with interactive audit
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →