GITLEAKS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Git secrets scanner that detects hardcoded passwords, API keys, and tokens in git repos using regex and entropy analysis.
INSTALLATION#
brew install gitleaks # macOS go install github.com/gitleaks/gitleaks/v8@latest # Go # Or download binary from GitHub releases
SCANNING#
# Scan local repo (git history) gitleaks detect -s /path/to/repo # Scan current directory gitleaks detect # Scan only staged changes (pre-commit) gitleaks protect --staged # Scan specific commit range gitleaks detect --log-opts="--since=2024-01-01" gitleaks detect --log-opts="abc123..HEAD" # No git history (filesystem only) gitleaks detect --no-git -s /path/to/directory
OUTPUT#
gitleaks detect -f json -r results.json # JSON report gitleaks detect -f csv -r results.csv # CSV report gitleaks detect -f sarif -r results.sarif # SARIF gitleaks detect --verbose # Verbose output gitleaks detect --exit-code 1 # Non-zero on findings
CONFIGURATION#
# Custom config file
gitleaks detect -c custom-config.toml
# Default config: .gitleaks.toml in repo root
# Example .gitleaks.toml:
title = "Custom Gitleaks Config"
[[rules]]
id = "aws-access-key"
description = "AWS Access Key"
regex = '''AKIA[0-9A-Z]{16}'''
tags = ["aws", "key"]
[[rules]]
id = "generic-password"
description = "Generic Password"
regex = '''(?i)password\s*=\s*['"][^'"]{8,}['"]'''
tags = ["password"]
# Allowlist (ignore false positives)
[allowlist]
paths = ["vendor/", "node_modules/", "*.test.js"]
commits = ["abc123def456"]
regexes = ["EXAMPLE_KEY"]
PRE-COMMIT HOOK#
# Install as pre-commit hook
# In .pre-commit-config.yaml:
repos:
- repo: https://github.com/gitleaks/gitleaks
rev: v8.18.0
hooks:
- id: gitleaks
# Or manual hook (.git/hooks/pre-commit):
#!/bin/bash
gitleaks protect --staged --exit-code 1
# Baseline (ignore existing secrets)
gitleaks detect --baseline-path baseline.json
gitleaks detect --baseline-path baseline.json --exit-code 1
TIPS#
- Use protect (not detect) for pre-commit hooks - Baseline file allows gradual remediation - SARIF output for GitHub/GitLab security dashboards - Combine with TruffleHog (TruffleHog verifies, Gitleaks is faster) - Custom rules in .gitleaks.toml for org-specific patterns - --no-git mode scans filesystems without git - Allowlist paths to reduce false positives - Run in CI/CD with --exit-code 1 as quality gate - Entropy-based detection catches non-pattern secrets - Scan all branches, not just main