{"_id":"@arunjayaraj/secret-scanner-cli","_rev":"2-29d9d906a7329513c83e7bb71b96890a","name":"@arunjayaraj/secret-scanner-cli","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@arunjayaraj/secret-scanner-cli","version":"1.0.0","keywords":["security","secrets","scanner","git","pre-commit","sensitive-data"],"author":{"name":"arun jayaraj"},"license":"MIT","_id":"@arunjayaraj/secret-scanner-cli@1.0.0","maintainers":[{"name":"arunjayaraj","email":"arunstallion49@gmail.com"}],"homepage":"https://github.com/yourusername/secret-scanner#readme","bugs":{"url":"https://github.com/yourusername/secret-scanner/issues"},"bin":{"secret-scan":"bin/scan.js"},"dist":{"shasum":"0e7237d6ffc40d1c868e8ab4284993a55ecf5f79","tarball":"https://registry.npmjs.org/@arunjayaraj/secret-scanner-cli/-/secret-scanner-cli-1.0.0.tgz","fileCount":6,"integrity":"sha512-oudpqTdNia7icizBBiXy7ekl+uG2SDCSd4z+wmOgcLkV11ZutT0umVx96Byhg4jc9Ljb+B6pqKt3D9Lu5Z5E4A==","signatures":[{"sig":"MEYCIQDsNhXPq10Mzgq95Z2viruZHlF4BpU1Sh9wjgBsSyznmgIhALgbb69uD739kRHKcdGd+i1NZI6lxfK4nx5OO8lKb4WH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9164},"main":"src/main.js","type":"module","engines":{"node":">=14.16"},"scripts":{"scan":"node bin/scan.js","test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"arunjayaraj","email":"arunstallion49@gmail.com"},"repository":{"url":"git+https://github.com/yourusername/secret-scanner.git","type":"git"},"_npmVersion":"10.9.0","description":"A tool to scan codebases for potential secrets and sensitive information","directories":{},"_nodeVersion":"20.16.0","dependencies":{"chalk":"^5.3.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/secret-scanner-cli_1.0.0_1742149607203_0.5768576769850371","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2025-03-16T18:26:47.129Z","modified":"2025-03-16T18:54:05.144Z","1.0.0":"2025-03-16T18:26:47.392Z"},"bugs":{"url":"https://github.com/yourusername/secret-scanner/issues"},"author":{"name":"arun jayaraj"},"license":"MIT","homepage":"https://github.com/yourusername/secret-scanner#readme","keywords":["security","secrets","scanner","git","pre-commit","sensitive-data"],"repository":{"url":"git+https://github.com/yourusername/secret-scanner.git","type":"git"},"description":"A tool to scan codebases for potential secrets and sensitive information","maintainers":[{"name":"arunjayaraj","email":"arunstallion49@gmail.com"}],"readme":"# Secret Scanner\r\n\r\nA powerful tool to scan your codebase for potential secrets and sensitive information. It helps prevent accidental commits of sensitive data by detecting various types of secrets including:\r\n\r\n- API Keys\r\n- Passwords\r\n- Database URLs\r\n- JWT Tokens\r\n- AWS Access Keys\r\n- Stripe API Keys\r\n- GitHub Tokens\r\n- SSH Private Keys\r\n- And more...\r\n\r\n## Installation\r\n\r\n```bash\r\nnpm install -g secret-scanner\r\n```\r\n\r\n## Usage\r\n\r\n### Scan Current Directory\r\n```bash\r\nnpm scan\r\n```\r\n\r\n### Scan Specific Directory\r\n```bash\r\nnpm scan /path/to/directory\r\n```\r\n\r\n### Use as a Pre-commit Hook\r\n\r\nAdd to your package.json:\r\n```json\r\n{\r\n  \"scripts\": {\r\n    \"precommit\": \"npm scan\"\r\n  }\r\n}\r\n```\r\n\r\nThen install husky:\r\n```bash\r\nnpm install husky --save-dev\r\nnpx husky install\r\nnpx husky add .husky/pre-commit \"npm run precommit\"\r\n```\r\n\r\n## Features\r\n\r\n- Fast parallel scanning using worker threads\r\n- Detects multiple types of secrets\r\n- Shows exact line numbers where secrets are found\r\n- Configurable ignore paths\r\n- Git integration\r\n- Colored output for better readability\r\n\r\n## Detected Secret Types\r\n\r\n- API Keys: Generic API keys and tokens\r\n- Passwords: Password fields in code or config files\r\n- Database URLs: Connection strings for various databases\r\n- JWT Tokens: JSON Web Tokens\r\n- AWS Access Keys: AWS access key IDs and secret access keys\r\n- Stripe API Keys: Both test and live keys\r\n- GitHub Tokens: Personal access tokens\r\n- SSH Private Keys: RSA, DSA, EC, and OpenSSH keys\r\n- Basic Auth: URLs with embedded credentials\r\n- OAuth Tokens: Various OAuth token formats\r\n- Generic Secrets: Other potential secret patterns\r\n\r\n## Contributing\r\n\r\nContributions are welcome! Please feel free to submit a Pull Request.\r\n\r\n## License\r\n\r\nMIT ","readmeFilename":"README.md"}