On this page
Overview
Gitleaks is a secret scanner for credentials, API keys, tokens, and similar data embedded in repositories or filesystems. It scans Git patch history, directories/files, or stdin and supports built-in and custom TOML rules, allowlists, baselines, and machine-readable reports.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Scan Git history, directories, files, and stdin
gitleaks git scans repository history using git log -p, while dir checks working trees or arbitrary paths and stdin accepts streamed input.
Sources: [1]
Customize detection with regex, entropy, keywords, and allowlists
The default configuration defines secret-specific regexes, entropy thresholds, keywords, and allowlists, and projects can extend or replace those rules with TOML configuration.
Use baselines and machine-readable reports in CI
Existing findings can be captured as a baseline so later scans focus on new issues. Reports can be emitted as JSON, CSV, JUnit, SARIF, or templates.
Sources: [1]
Best fit
Fits pre-commit and CI workflows that need early credential-leak detection
The same scanner can run as a local CLI, pre-commit hook, or GitHub Action, making it useful for consistent secret detection across developer and CI environments.
Sources: [1]
Before adoption
Redact finding output so the scanner does not become another secret leak
Verbose output and reports may contain detected values. Use --redact for shared logs and CI artifacts, restrict report access, and keep allowlists narrow enough that real secrets are not silently excluded.
Sources: [1]
Official sources
- [1]Gitleaks v8.30.1 README(2026-10-04)
- [2]Gitleaks v8.30.1 release(2026-10-04)
- [3]Gitleaks v8.30.1 default configuration(2026-10-04)
- [4]Gitleaks v8.30.1 Go module(2026-10-04)
- [5]Gitleaks MIT license(2026-10-04)
Supplemental curator note
Prevent the scanner output from becoming another secret leak: use --redact for CI/shared reports. Since v8.19, prefer git, dir, and stdin over the deprecated detect and protect commands.
Try it in 3 steps
- 1
Fetch the Gitleaks v8.30.1 source
Pin the checkout to the stable release tag. The source build expects the Go 1.24.11 generation declared in go.mod.
git clone --depth 1 --branch v8.30.1 https://github.com/gitleaks/gitleaks.git gitleaks-8.30.1 - 2
Build a local CLI binary
Build inside the repository without installing the binary system-wide.
cd gitleaks-8.30.1 && mkdir -p bin && go build -o bin/gitleaks ./cmd/gitleaks - 3
Scan only harmless stdin
Validate the CLI and stdin mode without scanning a real repository or credential. Use
--redactwhen real secrets could appear in shared logs.cd gitleaks-8.30.1 && ./bin/gitleaks version && printf 'hello from gitleaks\n' | ./bin/gitleaks stdin --no-banner
Growth
Growth trends · Last 30 days
29,644 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 0
- Open PRs
- 219
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- security
- security-tools
- git
- golang
- go
- secret
- gitleaks
- devsecops
- hacktoberfest
- ci-cd
- cicd
- cli
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Dokku32,164 Stars
2 shared tag(s) · Same language
turn a single Linux VM into a PaaS from git push through build, release, and routing
Go - Consul30,091 Stars
2 shared tag(s) · Same language
combine service discovery, health checks, service mesh, and API gateway capabilities for distributed infrastructure
Go - kube-bench8,209 Stars
3 shared tag(s) · 2 shared category(s) · Same language
audit Kubernetes node and cluster configuration against CIS Benchmark checks
Go - Trivy38,205 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Scan images, filesystems, repositories, VMs, and Kubernetes for CVEs, secrets, IaC issues, and licenses
Go - OSV-Scanner11,135 Stars
3 shared tag(s) · 1 shared category(s) · Same language
scan lockfiles, source trees, containers, and SBOMs for dependency vulnerabilities using OSV data
Go - mkcert59,717 Stars
2 shared tag(s) · 2 shared category(s) · Same language
create a local CA and easily issue browser-trusted TLS certificates for localhost and development domains
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.