repo-supervisor
Scan your code for security misconfiguration, search for passwords and secrets. :mag: (by auth0)
shhgit
Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories. (by eth0izzle)
SurveyJS - Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App
With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.
surveyjs.io
featured
repo-supervisor | shhgit | |
---|---|---|
2 | 7 | |
621 | 3,788 | |
- | - | |
0.0 | 0.0 | |
11 months ago | 8 months ago | |
JavaScript | JavaScript | |
MIT License | MIT License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
repo-supervisor
Posts with mentions or reviews of repo-supervisor.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-08-09.
-
Is there any way you can be hacked if you have a secret route
Hackers might scan your app with tools that look for strings that appear to have high entropy, as hashes tend to have. repo-supervisor from auth0 does that with their so called „entropy meter“ to find secrets and passwords.
- Ask HN: What are the best automated tools for keeping credentials out of GitHub?
shhgit
Posts with mentions or reviews of shhgit.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-12-20.
- Tencent WeChat is now a GitHub secret scanning partner
- Why do people use plain text for usernames and passwords on Github? A cautionary tale.
-
Searching across github
Shhgit is a really neat tool for this
- Around 50,000 GitHub credentials leaked as metadata inside commits
-
TruffleHog v3 – Detect and automatically verify over 600 credential types
There are a lot of secret detection tools out there. It probably is going to depend a lot on the specific features you care about. I personally really like shhgit[0] which is MIT licensed and is the tool I've found to most match my workflows.
[0]: https://github.com/eth0izzle/shhgit
-
My MetaMask Private Keys Stolen from GitHub Private Repo in 1 Hour
Assuming that the person you were working with didn't drain your wallet, there are many tools which can be used to actively monitor for commits being done on GitHub with secrets of sort.
The first one that comes to my mind is shhgit (https://github.com/eth0izzle/shhgit)
Anyone can self host it and then add multiple GitHub Dev keys to it. Then this can be used to monitor GitHub commits being done, majority of which can be categorized as "secrets".
- Ask HN: What are the best automated tools for keeping credentials out of GitHub?
What are some alternatives?
When comparing repo-supervisor and shhgit you can also consider the following projects:
trufflehog - Find and verify secrets
git-secrets - Prevents you from committing secrets and credentials into git repositories