{"_id":"@bobfromarcher/leaksweep","_rev":"2-dd5522def635fb11b0242cd1b0d6da6e","name":"@bobfromarcher/leaksweep","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@bobfromarcher/leaksweep","version":"1.0.0","keywords":["secrets","security","secret-scanning","credentials","pre-commit","git-hook","entropy","leak","ci","cli","zero-dependency","devtools"],"author":{"name":"bobfromarcher"},"license":"MIT","_id":"@bobfromarcher/leaksweep@1.0.0","maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"homepage":"https://github.com/bobfromarcher/leaksweep#readme","bugs":{"url":"https://github.com/bobfromarcher/leaksweep/issues"},"bin":{"leaksweep":"bin/leaksweep.js"},"dist":{"shasum":"c07d1a9bd27832040213d1709ca4cc998cc1279c","tarball":"https://registry.npmjs.org/@bobfromarcher/leaksweep/-/leaksweep-1.0.0.tgz","fileCount":4,"integrity":"sha512-6UGbOmf5HgtjseVJtxYTWBv6mlUsVG8SmQBYk1ZILcB/jzObxTBlXyKVjayrEbTMVobD7M4E6rBUCPKikV7azA==","signatures":[{"sig":"MEYCIQCldHoO4l93CjebiEwM0oqMimlg/lYsz0EC7oxB3GlF2gIhAI6ktEGNziyVweB56YgrAADlTExLZdvKColRgaZ/+Szo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13530},"engines":{"node":">=16"},"gitHead":"3e0ae55850a0808d619e3f9995309d375cc88251","scripts":{"test":"node test/test.js","start":"node bin/leaksweep.js"},"_npmUser":{"name":"bobfromarcher","email":"chrisbellth@gmail.com"},"repository":{"url":"git+https://github.com/bobfromarcher/leaksweep.git","type":"git"},"_npmVersion":"11.11.0","description":"Scan your code for committed secrets (API keys, tokens, private keys, high-entropy strings) before they hit GitHub. Pre-commit hook + CI gate. Zero dependencies.","directories":{},"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/leaksweep_1.0.0_1781946810730_0.39670575330595614","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bobfromarcher/leaksweep","publishConfig":{"access":"public"},"version":"1.0.1","description":"Scan your code for committed secrets (API keys, tokens, private keys, high-entropy strings) before they hit GitHub. Pre-commit hook + CI gate. Zero dependencies.","bin":{"leaksweep":"bin/leaksweep.js"},"scripts":{"test":"node test/test.js","start":"node bin/leaksweep.js"},"keywords":["secrets","security","secret-scanning","credentials","pre-commit","git-hook","entropy","leak","ci","cli","zero-dependency","devtools"],"author":{"name":"bobfromarcher"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/bobfromarcher/leaksweep.git"},"bugs":{"url":"https://github.com/bobfromarcher/leaksweep/issues"},"homepage":"https://github.com/bobfromarcher/leaksweep#readme","engines":{"node":">=16"},"gitHead":"bf40076d730b747fda4286682088f59715a27e08","_id":"@bobfromarcher/leaksweep@1.0.1","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-qIislBTp/PGf4zOResd8YzAb1PZHEKBpTxI7k6aHQ4M7aHiNpxi8OCCxUj+o87/HAd4tPyID7Yh8iGt+4vd2Jw==","shasum":"35889cc8315b26679ae89b82f2e9cfda6a452ed7","tarball":"https://registry.npmjs.org/@bobfromarcher/leaksweep/-/leaksweep-1.0.1.tgz","fileCount":4,"unpackedSize":13260,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCM+xsEHQqolDhUJYxtFvWN4Hm2kSQPfEi4YR7J7DlDwQIhAPeq8y9aqHhnnf0V//FBpghBwcnC67QzZHgBUqxPQfns"}]},"_npmUser":{"name":"bobfromarcher","email":"chrisbellth@gmail.com"},"directories":{},"maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/leaksweep_1.0.1_1781948743598_0.37074485954300873"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-20T09:13:30.634Z","modified":"2026-06-20T09:45:43.851Z","1.0.0":"2026-06-20T09:13:30.857Z","1.0.1":"2026-06-20T09:45:43.735Z"},"bugs":{"url":"https://github.com/bobfromarcher/leaksweep/issues"},"author":{"name":"bobfromarcher"},"license":"MIT","homepage":"https://github.com/bobfromarcher/leaksweep#readme","keywords":["secrets","security","secret-scanning","credentials","pre-commit","git-hook","entropy","leak","ci","cli","zero-dependency","devtools"],"repository":{"type":"git","url":"git+https://github.com/bobfromarcher/leaksweep.git"},"description":"Scan your code for committed secrets (API keys, tokens, private keys, high-entropy strings) before they hit GitHub. Pre-commit hook + CI gate. Zero dependencies.","maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"readme":"# leaksweep\n\n[![npm](https://img.shields.io/npm/v/@bobfromarcher/leaksweep?color=cb3837&logo=npm)](https://www.npmjs.com/package/@bobfromarcher/leaksweep)\n[![CI](https://github.com/bobfromarcher/leaksweep/actions/workflows/ci.yml/badge.svg)](https://github.com/bobfromarcher/leaksweep/actions/workflows/ci.yml)\n[![license](https://img.shields.io/npm/l/@bobfromarcher/leaksweep?color=blue)](LICENSE)\n[![zero deps](https://img.shields.io/badge/dependencies-0-success)](package.json)\n\nScans your code for committed secrets: API keys, tokens, private keys and high-entropy strings. Run it as a pre-commit hook to stop a secret before it is committed, or in CI to fail the build if one slips through. No dependencies, no AI.\n\n<p align=\"center\"><img src=\"demo.svg\" alt=\"leaksweep flagging committed secrets\" width=\"500\"></p>\n\nSecrets are always masked in the output. leaksweep never prints the full value, so the report itself is safe to paste into a ticket or a CI log.\n\n## Install\n\n```bash\nnpm install -g @bobfromarcher/leaksweep\n# or once:\nnpx @bobfromarcher/leaksweep\n```\n\n## Use it as a pre-commit hook\n\nThe point is to catch the secret before it is committed:\n\n```bash\n# .git/hooks/pre-commit\n#!/bin/sh\nnpx @bobfromarcher/leaksweep --staged || exit 1\n```\n\n`--staged` scans only what you have staged, so the hook is fast.\n\n## Use it in CI\n\n```yaml\n# .github/workflows/secrets.yml\n- run: npx @bobfromarcher/leaksweep\n```\n\nA non-zero exit on any finding fails the build.\n\n## Usage\n\n```bash\nleaksweep [path] [options]\n```\n\n| Option | Description |\n| --- | --- |\n| `--staged` | Scan only git-staged changes (pre-commit hook mode) |\n| `--all` | Walk the filesystem instead of git-tracked files |\n| `--json` | Output JSON |\n| `--quiet`, `-q` | No output, just the exit code |\n| `-h, --help` | Show help |\n| `-v, --version` | Show version |\n\n## What it detects\n\nAWS access keys and secret keys, GitHub tokens and fine-grained PATs, GitLab tokens, Slack tokens and webhooks, Stripe live keys, Google API keys, npm tokens, OpenAI keys, Twilio and SendGrid keys, JWTs, PEM private-key blocks, and a generic high-entropy detector for anything assigned to a `secret`, `token`, `password` or `api_key` style name.\n\nObvious placeholders such as `your_api_key_here`, `xxxx`, `<token>` and `example`, plus low-entropy dummy values, are filtered out to keep the noise down.\n\nleaksweep is a fast first line of defense, not a guarantee. It favors high-signal matches over exhaustive coverage. Pair it with secret rotation and server-side scanning for defense in depth.\n\n## Development\n\n```bash\ngit clone https://github.com/bobfromarcher/leaksweep\ncd leaksweep\nnode test/test.js\n```\n\nCI runs the suite on Node 18, 20 and 22 across Linux, macOS and Windows.\n\n## License\n\nMIT, bobfromarcher.\n","readmeFilename":"README.md"}