Secret scanning

A push holding an API key or password is rejected before it lands.

Built on gitleaks

Plans: Every plan, including the free app

What you get

  • Every push checked for keys and passwords
  • The push refused before anything is stored
  • The file, line and kind of key named in the message
  • The same check in whisk doctor, before the push
  • The value itself never printed
  • Your own rules in a .gitleaks.toml file

How it works

Every push to an app's Git repository is checked by gitleaks, the open-source secret scanner, before Whisk stores it. A push holding something that looks like an API key, a private key or a connection string with a password is refused with SECRET_IN_COMMIT.

The message names the file, the line and the kind of key, and says what to do: remove the value, declare it as a secret and change the key with the provider. The value itself is never shown, in the message or in a log.

whisk doctor runs the same gitleaks rules on the developer's machine, so a repository that passes doctor passes the push. The Whisk CLI is open source under the MIT licence.

Example

A food distributor's coding agent pastes a payment provider's live key into a config file while testing. The push is refused, the agent moves the key to a secret, and the owner pastes the value into the dashboard. The key never reaches the repository or its history.

For your coding agent

whisk doctor
whisk errors SECRET_IN_COMMIT

Doctor rule W010 runs the same scan as the push, and whisk errors prints the full fix. Every code is in the error reference, and every doctor rule in the doctor reference.

All features