Secret scanning
A push holding an API key or password is rejected before it lands.
Built on gitleaks
Plans: Every plan, including the free app
What you get
- Every push checked for keys and passwords
- The push refused before anything is stored
- The file, line and kind of key named in the message
- The same check in
whisk doctor, before the push - The value itself never printed
- Your own rules in a
.gitleaks.tomlfile
How it works
Every push to an app's Git repository is checked by gitleaks, the open-source secret scanner, before Whisk stores it. A push holding something that looks like an API key, a private key or a connection string with a password is refused with SECRET_IN_COMMIT.
The message names the file, the line and the kind of key, and says what to do: remove the value, declare it as a secret and change the key with the provider. The value itself is never shown, in the message or in a log.
whisk doctor runs the same gitleaks rules on the developer's machine, so a repository that passes doctor passes the push. The Whisk CLI is open source under the MIT licence.
Example
A food distributor's coding agent pastes a payment provider's live key into a config file while testing. The push is refused, the agent moves the key to a secret, and the owner pastes the value into the dashboard. The key never reaches the repository or its history.
For your coding agent
whisk doctor whisk errors SECRET_IN_COMMIT
Doctor rule W010 runs the same scan as the push, and whisk errors prints the full fix. Every code is in the error reference, and every doctor rule in the doctor reference.