Check Git-tracked files for new secrets
Problem and when to use it
Passwords, API tokens and other credentials can be committed to Git by mistake. Once pushed, they may be exposed to anyone with repository access and can remain in Git history even after the file is changed or deleted. Reviewing every file manually before merging is unreliable.
Run cd-detect-secrets locally or in CI to check Git-tracked files against a
reviewed detect-secrets registry. It fails the check for new, unrecorded
findings so they can be investigated before a change is merged. It scans the
current checkout, not historical commits or untracked files. Use
cd-record-secrets only for findings reviewed and
accepted by the team.
Inputs and example
Install the project and its detect-secrets dependency, and keep the reviewed registry under version control:
cd-detect-secrets --registry-file .secrets.baseline
The configured language plugin supplies exclusion patterns. Use
cd-record-secrets only after reviewing an accepted
finding.
Output
Exit status zero when tracked files match the registry; otherwise a failing status with the detected findings.
GitHub Actions example
After checkout and installation:
- run: cd-detect-secrets
See the repository's CI workflow for an example of a separate secrets check.