{"_id":"@danny1214/repocheck","_rev":"6-2fe82e2acadd563ca4a04dfc74d4bf6d","name":"@danny1214/repocheck","dist-tags":{"latest":"1.1.1"},"versions":{"1.0.0":{"name":"@danny1214/repocheck","version":"1.0.0","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"license":"MIT","_id":"@danny1214/repocheck@1.0.0","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"bin":{"repocheck":"bin/repocheck.js"},"dist":{"shasum":"cca0b31193e5a6a566dd008e89e3d4eaa13d12c9","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.0.0.tgz","fileCount":12,"integrity":"sha512-QFwXm5vbKJOKMWeEOlIkbI03jg71ahHvP55N1pb3VpiSh2l6RUJjiVYUxjnBA7wET3Dc9T7fB++1y/4hvWRXSg==","signatures":[{"sig":"MEQCIFcK4E2+BMFJIIN4C8Qbhgwg2Vvxuf138gd0Qr+46qH9AiAHcmiO4fBFxrOHzfUewfMWFbVnwaHnJg8qrIpX7wc47g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41047},"main":"lib/index.js","engines":{"node":">=14"},"gitHead":"1d081f919ac7ae644bbac0950f37b92034677880","scripts":{"test":"node test/repocheck.test.js"},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"_npmVersion":"10.9.8","description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/repocheck_1.0.0_1785554589254_0.06628001712408382","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@danny1214/repocheck","version":"1.0.1","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"license":"MIT","_id":"@danny1214/repocheck@1.0.1","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"bin":{"repocheck":"bin/repocheck.js"},"dist":{"shasum":"c0e906beea0a1ce5d6c4af4c2b672751e3cb267a","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.0.1.tgz","fileCount":12,"integrity":"sha512-b+ayjknJNJT4WZSy0G0fOM8UdHFMnEXMVW9VLHksAliaj7RVEluefdYD2Ha343SnW0zXG6Yr4DOv10/U+7cARQ==","signatures":[{"sig":"MEUCIQDbT+pGSfLlxaNmVIdhvoT1uSs+5vv9lSpSZq1RxkuhTAIgF41NH+q+wzdXt4zzwFkDVahMNQuS1O3k7Oab9iEjwTk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41803},"main":"lib/index.js","engines":{"node":">=14"},"gitHead":"1d081f919ac7ae644bbac0950f37b92034677880","scripts":{"test":"node test/repocheck.test.js"},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"_npmVersion":"10.9.8","description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/repocheck_1.0.1_1785557671841_0.3087048071390226","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@danny1214/repocheck","version":"1.0.2","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"license":"MIT","_id":"@danny1214/repocheck@1.0.2","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"bin":{"repocheck":"bin/repocheck.js"},"dist":{"shasum":"880ae35d955c8b1e0501b23215c6571d8561a2cc","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.0.2.tgz","fileCount":12,"integrity":"sha512-7va8/VeYjCahDyDA15nCvOkkTA0HnHEygF6EBQ5TjidSq3WuPylJBCJ6bC1A7thDTzAIJ7dOxg855L0mNyr0kA==","signatures":[{"sig":"MEUCIQDz2uNfkC3rXFiXWm9Cm3Qs+6+MOUvYESPa4aAYW5yxcwIgdTMH6VEzRFUkMqwkEPNPd29RQzvpJrS9fIq2VCQiX1o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41803},"main":"lib/index.js","engines":{"node":">=14"},"gitHead":"1d081f919ac7ae644bbac0950f37b92034677880","scripts":{"test":"node test/repocheck.test.js"},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"_npmVersion":"10.9.8","description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/repocheck_1.0.2_1785557687961_0.7461091408630607","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@danny1214/repocheck","version":"1.0.3","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"license":"MIT","_id":"@danny1214/repocheck@1.0.3","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"bin":{"repocheck":"bin/repocheck.js"},"dist":{"shasum":"147a74f391d6628d349943ddb20e7a6fdadea905","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.0.3.tgz","fileCount":11,"integrity":"sha512-dw9oCduWDau2rZkLoNYHpkH9T3Rm1etTHXiESl/ne53G6x+mBVUhn9opP9781X/J5PEIsurTtpMuXg/A/72JMA==","signatures":[{"sig":"MEUCIQDAmLFhFNXMZ8yZowIGmntY8pv6/vt0S4dhkWJKlbbyrAIgPUTFUiV0ebjAldIVRhBfLZBBme6b9vM5J+Zjz4ioG48=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35204},"main":"lib/index.js","engines":{"node":">=14"},"gitHead":"67f48b482ecb1a07c1f46a28380fcb0812868a3e","scripts":{"test":"node test/repocheck.test.js"},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"_npmVersion":"10.9.8","description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/repocheck_1.0.3_1785610847043_0.4789322473296205","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@danny1214/repocheck","version":"1.1.0","keywords":["security","audit","secrets","env","package.json","cli","devtools","git-history"],"license":"MIT","_id":"@danny1214/repocheck@1.1.0","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"bin":{"repocheck":"bin/repocheck.js"},"dist":{"shasum":"7c329fb881a6135ea4d1e580235408f2f3e74715","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.1.0.tgz","fileCount":12,"integrity":"sha512-RKnm9v43Loz5LesvHhybnACugfajpkOKspnaYyMTtDvGVUeB5XCRK0SgHXgCP5B8s1f6yiGUkXL2wdbHZMt4kg==","signatures":[{"sig":"MEQCICsnR4Lz1UXY0BqTHAyLVeEBgl8y12Uncb0/EGksincuAiB1KsLN9Xh9vKfonpwlzH4xMdrJqIWuW2kpY6d9usf5uA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41746},"main":"lib/index.js","engines":{"node":">=14"},"gitHead":"24079e61191970adb4252ff393a2ed4b48b95c32","scripts":{"test":"node test/repocheck.test.js && node test/gitHistory.test.js"},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"_npmVersion":"10.9.8","description":"One command to audit a repo: leaked secrets (including full git history), .env drift, and package.json hygiene issues.","directories":{},"_nodeVersion":"22.23.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/repocheck_1.1.0_1785639622251_0.48514165783088714","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@danny1214/repocheck","version":"1.1.1","description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","bin":{"repocheck":"bin/repocheck.js"},"main":"lib/index.js","scripts":{"test":"node test/repocheck.test.js"},"engines":{"node":">=14"},"license":"MIT","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"_id":"@danny1214/repocheck@1.1.1","gitHead":"424807fb87dd2317808fb8ddb3f764d6106a7109","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-nkYR2+gxghEY0GWY8LxKX13Z866/XVzHamXipokPWRgJFO71GdopWQU0lLtaPQ8ztdQlQP3kPASv/nlF2UBVWw==","shasum":"82968323c3f5c3b962047392e37be64751b185a9","tarball":"https://registry.npmjs.org/@danny1214/repocheck/-/repocheck-1.1.1.tgz","fileCount":12,"unpackedSize":41398,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCAsUujAVP0uLF7s5h6/jXftysi/rSGB/bVNY0/PGHR6QIgdjmdZK/SDl/+u3m8UOEnyu5v25Kv/vHc9/JKJIX3LEY="}]},"_npmUser":{"name":"danny1214","email":"dandylopez37@gmail.com"},"directories":{},"maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/repocheck_1.1.1_1785747625657_0.38046654440225836"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-01T03:23:09.087Z","modified":"2026-08-03T09:00:25.929Z","1.0.0":"2026-08-01T03:23:09.406Z","1.0.1":"2026-08-01T04:14:32.069Z","1.0.2":"2026-08-01T04:14:48.102Z","1.0.3":"2026-08-01T19:00:47.184Z","1.1.0":"2026-08-02T03:00:22.406Z","1.1.1":"2026-08-03T09:00:25.790Z"},"license":"MIT","keywords":["security","audit","secrets","env","package.json","cli","devtools"],"description":"One command to audit a repo: leaked secrets, .env drift, and package.json hygiene issues.","maintainers":[{"name":"danny1214","email":"dandylopez37@gmail.com"}],"readme":"# repocheck\n\nOne command to audit a repo for the three things that most often bite\ndevelopers before they ship: leaked secrets, `.env` drift, and unhealthy\n`package.json` hygiene.\n\nNo dependencies. No network calls. No telemetry. Runs entirely on your\nmachine against your local files.\n\n## Install\n\n```bash\nnpm install -g @danny1214/repocheck\nrepocheck --help\n```\n\n### From source (contributing / local dev only)\n\n```bash\ngit clone <this-repo> repocheck\ncd repocheck\nnpm link   # or: node bin/repocheck.js <path>\n```\n\n## Usage\n\n```bash\nrepocheck                # audit the current directory\nrepocheck ./my-project   # audit a specific path\nrepocheck --json         # machine-readable JSON output\nrepocheck --history      # also scan full git commit history for secrets\n```\n\nExit codes: `0` = clean, `1` = issues found, `2` = error running the audit.\nDesigned to be dropped into CI (`repocheck || exit 1`).\n\n## What it checks\n\n### 1. Leaked secrets\nScans every text file (skipping `.git`, `node_modules`, build output) for:\n- AWS access/secret keys\n- GitHub, Slack, Stripe, Google API tokens\n- JWTs\n- PEM-format private key blocks\n- Hardcoded password assignments\n- Database connection strings with embedded credentials\n- Any other high-entropy value assigned to a variable that looks like a\n  secret (`*_token`, `*_key`, `*_secret`, etc.)\n- Optionally, full git commit history (`--history`) — catches secrets that\n  were committed and later removed from the working tree but still live in\n  git log.\n\nAll matches are redacted in output (`AKIA...MNOP`) — never printed in full.\n\n### 2. `.env` drift\n- `.env` exists but no `.env.example`/`.env.sample` template for new\n  contributors\n- `.env.example` exists but there's no local `.env` to actually run the app\n- Keys present in one but not the other (drift between template and reality)\n- `.env` exists but isn't listed in `.gitignore` (the #1 way secrets get\n  committed by accident)\n\n### 3. `package.json` hygiene\n- Missing `name`, `version`, `license`, or `description`\n- Scripts that pipe a remote `curl` straight into a shell (supply-chain risk)\n- Dependencies installed directly from a URL instead of a registry version\n- Dependencies pinned to `*` or `latest` (non-reproducible installs)\n- No lockfile present (`package-lock.json` / `yarn.lock` / `pnpm-lock.yaml`)\n\n## Why one tool instead of three\n\nMost teams run a secret scanner, a linter, and maybe nothing for `.env`\nhygiene — as three separate tools with three separate configs. `repocheck`\nis the 80% version of all three in a single dependency-free script, meant\nto be the thing you actually run before every PR because it takes under a\nsecond and needs zero setup.\n\n## Testing\n\n```bash\nnpm test\n```\n\n26 tests, all passing, no external test framework required.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}