secret-scan

beta

High-throughput secret scanner for CI

A fast regex-based secret scanner built for CI pipelines: scans diffs and trees for API keys, tokens, and credentials, and fails the pipeline when it finds one.

v0.2.x — API may change before 1.0.

Language
Rust
License
MIT
Version
v0.2.3
Released
2026-08-24

Install

cargo install secretscan

How it works

Single Rust binary; walks the tree (or a provided diff), matches a curated detector set, exits non-zero on findings so CI can gate on it. Published on crates.io (3,100+ downloads).

Links