OSS TanbouSign in with GitHub

detect passwords, API keys, tokens, and other secrets in Git history, files, directories, and stdin

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
29,644
Primary language
Go
License
MIT
Repository last updated
Sep 30, 2026
On this page

Overview

Gitleaks is a secret scanner for credentials, API keys, tokens, and similar data embedded in repositories or filesystems. It scans Git patch history, directories/files, or stdin and supports built-in and custom TOML rules, allowlists, baselines, and machine-readable reports.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Scan Git history, directories, files, and stdin

gitleaks git scans repository history using git log -p, while dir checks working trees or arbitrary paths and stdin accepts streamed input.

Sources: [1]

Customize detection with regex, entropy, keywords, and allowlists

The default configuration defines secret-specific regexes, entropy thresholds, keywords, and allowlists, and projects can extend or replace those rules with TOML configuration.

Sources: [1][3]

Use baselines and machine-readable reports in CI

Existing findings can be captured as a baseline so later scans focus on new issues. Reports can be emitted as JSON, CSV, JUnit, SARIF, or templates.

Sources: [1]

Best fit

Fits pre-commit and CI workflows that need early credential-leak detection

The same scanner can run as a local CLI, pre-commit hook, or GitHub Action, making it useful for consistent secret detection across developer and CI environments.

Sources: [1]

Before adoption

Redact finding output so the scanner does not become another secret leak

Verbose output and reports may contain detected values. Use --redact for shared logs and CI artifacts, restrict report access, and keep allowlists narrow enough that real secrets are not silently excluded.

Sources: [1]

Pin v8 command and configuration behavior

Since v8.19, the older detect and protect commands are deprecated in favor of git, dir, and stdin. The v8.30.1 source specifies Go 1.24.11, and the default config carries a minimum-version field, so binary/config version skew matters.

Sources: [1][3][4]

Official sources

  1. [1]Gitleaks v8.30.1 README(2026-10-04)
  2. [2]Gitleaks v8.30.1 release(2026-10-04)
  3. [3]Gitleaks v8.30.1 default configuration(2026-10-04)
  4. [4]Gitleaks v8.30.1 Go module(2026-10-04)
  5. [5]Gitleaks MIT license(2026-10-04)
Supplemental curator note

Prevent the scanner output from becoming another secret leak: use --redact for CI/shared reports. Since v8.19, prefer git, dir, and stdin over the deprecated detect and protect commands.

Try it in 3 steps

  1. 1

    Fetch the Gitleaks v8.30.1 source

    Pin the checkout to the stable release tag. The source build expects the Go 1.24.11 generation declared in go.mod.

    git clone --depth 1 --branch v8.30.1 https://github.com/gitleaks/gitleaks.git gitleaks-8.30.1
  2. 2

    Build a local CLI binary

    Build inside the repository without installing the binary system-wide.

    cd gitleaks-8.30.1 && mkdir -p bin && go build -o bin/gitleaks ./cmd/gitleaks
  3. 3

    Scan only harmless stdin

    Validate the CLI and stdin mode without scanning a real repository or credential. Use --redact when real secrets could appear in shared logs.

    cd gitleaks-8.30.1 && ./bin/gitleaks version && printf 'hello from gitleaks\n' | ./bin/gitleaks stdin --no-banner
Check the official README

Growth

Growth trends · Last 30 days

29,644 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
0
Open PRs
219

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • security
  • security-tools
  • git
  • golang
  • go
  • secret
  • gitleaks
  • devsecops
  • hacktoberfest
  • ci-cd
  • cicd
  • cli
Stars
29,644
Forks
2,264
Watchers
184
Open issues
271
Contributors
211
Owner type
Organization
Primary language
Go
License
MIT
Repository last updated
Sep 30, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?