leaky-repo
whispers
DISCONTINUED
Our great sponsors
leaky-repo | whispers | |
---|---|---|
2 | 2 | |
211 | 463 | |
- | - | |
0.0 | 0.0 | |
11 months ago | 6 months ago | |
Python | Python | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
leaky-repo
-
Nosey Parker: a new scanner to find misplaced secrets in textual data and Git history
Also, I've built a repo of credentials and benchmarked several tools including trufflehog against it if you want to see how your tool and default ruleset stack up: https://github.com/Plazmaz/leaky-repo
-
Discover Hidden Secrets in Git Repos with Rust
At this point, we've succeeded at what we set out to create. I went ahead and scanned common testing repositories for this sort of thing like Plazmaz/leaky-repo and dijininja/leakyrepo. In general the program found all or most of the secrets. In the case of dijininja/leakyrepo it found a lot of RSA private keys which is acceptable but technically a misidentification. For Plazmaz/leaky-repo we find the majority of the keys although once again misidentify some. The decision to use rust makes performance really solid although still a little slow even for small repos. A couple good extensions to this to help with that could be adding a thread pool in order to scan objects in parallel. In more professional code, it seems more idiomatic for the scan_objects() function to return some objects of objects including their results rather than just printing the one containing secrets. For example, it could be formatted something like this:
whispers
We haven't tracked posts mentioning whispers yet.
Tracking mentions began in Dec 2020.
What are some alternatives?
ggshield - Find and fix 360+ types of hardcoded secrets and 70+ types of infrastructure-as-code misconfigurations.
repo-supervisor - Scan your code for security misconfiguration, search for passwords and secrets. :mag:
leakyrepo - A repo which contains lots of things which it shouldn't
deadshot - Deadshot is a Github pull request scanner to identify sensitive data being committed to a repository
JAZ - Find secrets hidden in commits
betterscan-ce - Code Scanning/SAST/Static Analysis/Linting using many tools/Scanners + OpenAI GPT with One Report (Code, IaC) - Betterscan Community Edition (CE)
yaml.el - YAML parser in Elisp
ssh-crypt - This tool helps you to keep passwords inside your shell scripts safely
knob - Key Negotiation Of Bluetooth (KNOB) attacks on Bluetooth BR/EDR and BLE [CVE-2019-9506]
noseyparker - Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.
tartufo - Searches through git repositories for high entropy strings and secrets, digging deep into commit history