GitHub Access Token Exposure

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • talisman

    Using a pre-commit hook, Talisman validates the outgoing changeset for things that look suspicious — such as tokens, passwords, and private keys.

  • https://thoughtworks.github.io/talisman/

  • tartufo

    Searches through git repositories for high entropy strings and secrets, digging deep into commit history

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • gitleaks

    Protect and discover secrets using Gitleaks 🔑

  • ggshield

    Find and fix 360+ types of hardcoded secrets and 70+ types of infrastructure-as-code misconfigurations.

  • git-secrets

    Prevents you from committing secrets and credentials into git repositories

  • secrets

    Discontinued A command-line tool to prevent committing secret keys into your source code [Moved to: https://github.com/sirwart/ripsecrets] (by sirwart)

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts