{"_id":"@mapbox/secret-shield","_rev":"117-452b111cc8ae554813527152b1fe8682","time":{"1.0.1":"2018-08-30T20:08:16.151Z","created":"2018-09-05T16:43:22.852Z","1.0.2":"2018-09-05T16:43:23.014Z","modified":"2023-01-12T12:36:24.369Z","1.0.3":"2021-10-13T19:41:33.743Z","1.0.4":"2021-10-13T20:05:16.542Z","1.0.5":"2022-09-22T18:50:17.183Z","1.0.6":"2022-11-09T14:51:50.871Z"},"name":"@mapbox/secret-shield","dist-tags":{"latest":"1.0.6"},"versions":{"1.0.2":{"name":"@mapbox/secret-shield","version":"1.0.2","description":"Search for secrets in the specified github repo","main":"index.js","scripts":{"test":"tape test/*.test.js | tap-diff","lint":"eslint -c .eslintrc.js *.js **/*.js"},"bin":{"secret-shield":"bin/secret-shield.js"},"author":{"name":"Mapbox"},"license":"ISC","dependencies":{"acorn":"^5.5.3","command-join":"^2.0.0","command-line-args":"^5.0.2","d3-queue":"^3.0.7","decrypt-kms-env":"^3.0.0","es6-promise":"^4.2.4","esprima":"^4.0.0","fast-fuzzy":"^1.5.0","find-in-files":"^0.5.0","git-clone":"^0.1.0","lodash":"^4.17.10","md5":"^2.2.1","p-queue":"^2.4.2","proxyquire":"^2.0.1","rewire":"^3.0.2","rimraf":"^2.6.2","semver":"^5.5.0","shelljs":"^0.8.1","simple-statistics":"^5.4.0","tty-table":"^2.6.2","uuid":"^3.2.1","yamljs":"^0.3.0"},"devDependencies":{"@mapbox/cloudfriend":"^1.9.0","@mapbox/dyno":"^1.4.1","@mapbox/watchbot":"^4.0.0","@octokit/rest":"^15.2.7","aws-sdk":"^2.230.1","eslint":"^4.17.0","got":"^8.3.1","sinon":"^6.0.0","tap-diff":"^0.1.1","tape":"^4.8.0"},"gitHead":"92b431e0252d40ad54a10860d1fb14de082c5c55","_id":"@mapbox/secret-shield@1.0.2","_npmVersion":"6.1.0","_nodeVersion":"10.5.0","_npmUser":{"name":"mapbox-npm-09","email":"accounts+npmjs-09@mapbox.com"},"dist":{"integrity":"sha512-Lna+8w3lb8IcbeUoE8icUJJZ4X0VH5hQusgN03RZwHm+hWn9twIer5P0TK5sOZDKSOEsAGiqKfnyGF5F2I4bIg==","shasum":"9f552ac45d4941d7cd0ab4c95af8502b47009236","tarball":"https://registry.npmjs.org/@mapbox/secret-shield/-/secret-shield-1.0.2.tgz","fileCount":76,"unpackedSize":693127,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbkAerCRA9TVsSAnZWagAAEfEQAIqUGl36hYey40xb33b9\nft0M+XWw/jXdzgVnYO8DA7W9JPRwnICzjgc3OVLS763OnRH+ZmIqwd16I7GK\nan9TcorMuZv/2nfnQy8RbmtbV2ywLYvfd3ESGWWB0qt8FUNSi/cnWiQrt7jh\nO0Lp6oowmLKK7xHHOewmHssnHfiF0rryUjMlCLpy3NX0siB5hNDX2f9NJt0k\nAgp9A1xej9FU2tsXEwO2Mgesc3uPO28hIKnfJsTWqZG0I9iI3nk6nBYYA161\n3PK0bObTELgM4sOYVZsB2W0h/z24Kqp8Aj1N9ouoiHDtB6AtZYCApfRGlVJ/\n53VljfPSWOsrjqgCh6kGR1gfzAV+PQ6akGMm61G02FtYkDQzIxOFJLUj3iYa\nMO/4n7qFOVU+PITp94a3TDATM/lV9urU0jOkOjexdvEGAncSi7FJnkjgFTxI\nijWZO7YH9qs8tZ+3aBQSHdsJp8M08bqrXpaPUjr8I8h++0AKJapWvXqBwl+s\n1mDOJBPhe56U//y+Z6L+kl5tbnilM4SHhDeeuKpe9qfQwLGWdu5uIwJi6u7u\noqkPB+exHqC8RaYugV8fcSAEuYrL4U9qfcLkgQGG8fjqKyvVnRw1VJIyjoDg\n9639C/5xRiyfQ/HOdEx1oYOJqwvkb210BdDjwjKIVbKV79IJsuaEGuaYQ9Rd\n/RBi\r\n=uaZS\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCitQYkqYQbxIOYRkIJ9gNbjDV26F94NEI8hy9aV3cibwIhANlWh68B18XhNPdmni98Q8wMlHNSpk1J3iUaUr6Hc3gP"}]},"maintainers":[{"name":"mapbox-admin","email":"accounts@mapbox.com"},{"name":"mapbox-machine-user","email":"accounts+npm-mapbox-machine-user@mapbox.com"},{"name":"mapbox-npm","email":"accounts+npmjs@mapbox.com"},{"name":"mapbox-npm-01","email":"accounts+npmjs-01@mapbox.com"},{"name":"mapbox-npm-02","email":"accounts+npmjs-02@mapbox.com"},{"name":"mapbox-npm-03","email":"accounts+npmjs-03@mapbox.com"},{"name":"mapbox-npm-04","email":"accounts+npmjs-04@mapbox.com"},{"name":"mapbox-npm-05","email":"accounts+npmjs-05@mapbox.com"},{"name":"mapbox-npm-06","email":"accounts+npmjs-06@mapbox.com"},{"name":"mapbox-npm-07","email":"accounts+npmjs-07@mapbox.com"},{"name":"mapbox-npm-08","email":"accounts+npmjs-08@mapbox.com"},{"name":"mapbox-npm-09","email":"accounts+npmjs-09@mapbox.com"},{"name":"mapbox-npm-advanced-actions","email":"accounts+npmjs-advanced-actions@mapbox.com"},{"name":"mapbox-npm-ci","email":"accounts+npmjs-npm-ci@mapbox.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/secret-shield_1.0.2_1536165802910_0.08391177360624003"},"_hasShrinkwrap":false},"1.0.4":{"name":"@mapbox/secret-shield","version":"1.0.4","description":"Search for secrets in the specified github repo","main":"index.js","scripts":{"test":"tape test/*.test.js | tap-diff","lint":"eslint -c .eslintrc.js *.js **/*.js"},"engines":{"node":">=10"},"bin":{"secret-shield":"bin/secret-shield.js"},"author":{"name":"Mapbox"},"license":"ISC","dependencies":{"acorn":"^5.7.4","command-join":"^2.0.0","command-line-args":"^5.0.2","d3-queue":"^3.0.7","decrypt-kms-env":"^3.0.0","es6-promise":"^4.2.4","esprima":"^4.0.0","fast-fuzzy":"^1.5.0","find-in-files":"^0.5.0","git-clone":"^0.1.0","lodash":"^4.17.15","md5":"^2.2.1","p-queue":"^2.4.2","proxyquire":"^2.0.1","rewire":"^3.0.2","rimraf":"^2.6.2","semver":"^5.5.0","shelljs":"^0.8.3","simple-statistics":"^5.4.0","tty-table":"^4.1.1","uuid":"^3.2.1","yamljs":"^0.3.0"},"devDependencies":{"@mapbox/cloudfriend":"^1.9.0","@mapbox/dyno":"^1.4.1","@mapbox/watchbot":"^4.20.2","@octokit/rest":"^15.18.3","aws-sdk":"^2.883.0","eslint":"^4.17.0","got":"^8.3.1","sinon":"^6.0.0","tap-diff":"^0.1.1","tape":"^4.13.3"},"gitHead":"434ebac81cee4c7a63733bf7161e70af2821133d","_id":"@mapbox/secret-shield@1.0.4","_nodeVersion":"15.8.0","_npmVersion":"8.0.0","dist":{"integrity":"sha512-Y51BVQi35qYmaWFQiUOzKAUx77rQNrtfWwyI2l8a7iL5Ibjxv0JL4QToNE5WzA7z3h3f91yCLkMio9S6uOd56g==","shasum":"fea98f0fb9803c9c3b945c7f300a94fb1ad724ab","tarball":"https://registry.npmjs.org/@mapbox/secret-shield/-/secret-shield-1.0.4.tgz","fileCount":78,"unpackedSize":695689,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJh2QlNCRA9TVsSAnZWagAAk6UP/jwy567DLAgqYdjtyGAm\nX0h5jjcmPCjoljMIfZS8ceCnEwi1xTRCRFa5mtx3mIn0z28CsD9iIlkJ3/jE\nMgRQOtfs9N4OUoAtVdzAYPxiK+jeBaD1MZnzw6QPMOWCttomzV6ALB+BnRut\n8Dn3ndmWWPH3RFWko+HNqrzjnGW7MJVdvsFg6eMQoiE0Wq+cYp4egOim1Udu\nyWQ0KNfxpsXZ/e4+6n84Cp83cCFGft1j9hi7e+Fb+JVGE6hhu/ev2XEO/HP8\nr8Ru9PKA85qVDrY+08lSD6OAOYmdKvOEBq3sEJ1F2ZenAFcN8iJUeeJEpI4/\nBCh6Xp2EnTFGSkwk8pW8Vhh7czoH33yLQcx6p6i2lUs8jv6clezZGWXpR2sv\n/1xNdMIDd0jlp0wmxsB2yVUDwLkFAQUGK81HaS7M7kgdsRfA9QH796PcXQyQ\nCVHI+HVze13w1HT5erhFpaGzIwYdINyYK4ODHvYCOa2ErWDT3mbFLnZ7esZ+\nW8Bh4mLFDXkj9oTXbBJS6++5SbhobT06606IU1ApoNWyETVsnSxVM5OLBCAX\nqsmQjAhPOpxyHWDNDOC5gRAiw0U30V2MPmPpwGx/qO6ybrD2var20qmQHBlb\nSBXpYSEzIQegNMSUcraOnvqi1b5GKLzbJqeH/c684QW8opw00iGigQ6mVv5i\nlIMd\r\n=gg9S\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGvI5rkh1BXh0kzPLImS08zEU6pElBuun4jMOmZ9tjerAiBIlwkKVFz5LiJ+U22XptWoLLP63q8sTaIgC2ya1OcvIg=="}]},"_npmUser":{"name":"mapbox-npm-03","email":"accounts+npmjs-03@mapbox.com"},"directories":{},"maintainers":[{"name":"mapbox-npm-01","email":"accounts+npmjs-01@mapbox.com"},{"name":"mapbox-npm-02","email":"accounts+npmjs-02@mapbox.com"},{"name":"mapbox-npm-07","email":"accounts+npmjs-07@mapbox.com"},{"name":"mapbox-npm-03","email":"accounts+npmjs-03@mapbox.com"},{"name":"mapbox-npm-04","email":"accounts+npmjs-04@mapbox.com"},{"name":"mapbox-npm-09","email":"accounts+npmjs-09@mapbox.com"},{"name":"mapbox-npm-05","email":"accounts+npmjs-05@mapbox.com"},{"name":"mapbox-npm-06","email":"accounts+npmjs-06@mapbox.com"},{"name":"mapbox-npm-08","email":"accounts+npmjs-08@mapbox.com"},{"name":"mapbox-npm-advanced-actions","email":"accounts+npmjs-advanced-actions@mapbox.com"},{"name":"mapbox-npm-ci","email":"accounts+npmjs-npm-ci@mapbox.com"},{"name":"mapbox-npm","email":"accounts+npmjs@mapbox.com"},{"name":"mapbox-admin","email":"accounts@mapbox.com"},{"name":"mapbox-machine-user","email":"accounts+npm-mapbox-machine-user@mapbox.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/secret-shield_1.0.4_1634155516315_0.47488714924474507"},"_hasShrinkwrap":false},"1.0.5":{"name":"@mapbox/secret-shield","version":"1.0.5","description":"Search for secrets in the specified github repo","main":"index.js","scripts":{"test":"tape test/*.test.js | tap-spec","lint":"eslint -c .eslintrc.js *.js **/*.js"},"engines":{"node":">=14"},"bin":{"secret-shield":"bin/secret-shield.js"},"author":{"name":"Mapbox"},"license":"ISC","dependencies":{"acorn":"^8.7.1","command-join":"^3.0.0","command-line-args":"^5.2.1","d3-queue":"^3.0.7","decrypt-kms-env":"^3.0.0","es6-promise":"^4.2.8","esprima":"^4.0.1","fast-fuzzy":"^1.11.1","find-in-files":"^0.5.0","git-clone":"^0.2.0","lodash":"^4.17.21","md5":"^2.3.0","p-queue":"^7.2.0","proxyquire":"^2.1.3","rewire":"^6.0.0","rimraf":"^3.0.2","semver":"^7.3.7","shelljs":"^0.8.5","simple-statistics":"^7.7.5","tty-table":"^4.1.5","uuid":"^8.3.2","yamljs":"^0.3.0"},"devDependencies":{"@mapbox/cloudfriend":"^5.1.1","@mapbox/dyno":"^1.5.1","@mapbox/watchbot":"^8.0.0","@octokit/rest":"^18.12.0","aws-sdk":"^2.1129.0","eslint":"^8.14.0","got":"^12.0.4","sinon":"14.0.0","tap-spec":"^5.0.0","tape":"^5.5.3"},"gitHead":"a6a09b8967fe901a7795f35cd8eebfd34dd01384","_id":"@mapbox/secret-shield@1.0.5","_nodeVersion":"16.16.0","_npmVersion":"8.19.2","dist":{"integrity":"sha512-BPKsYgkhtxt+qh8yWHWp/cD80ewyfoYz/4IBB4NPGmjVE5V0zAbIZ2IndavjdNjdmgsizVJu2utiRcNLbAWQvw==","shasum":"29f06ed9b8d366a6d505947e26773f9b2c2be2b6","tarball":"https://registry.npmjs.org/@mapbox/secret-shield/-/secret-shield-1.0.5.tgz","fileCount":79,"unpackedSize":695779,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDCb9c230IGeXN06g5d15mZBLqt2q9UvfJWatks70LLDwIhAIQF2qgoBv/2Ox12KNy98bS0FDHs+dKKnNBC3Ce6l5sj"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjLK5pACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpdjg/9F4i+ohiCkZT+RwMVbMK6HkVgaCYKnKu7rJiyTFGh6Bi+w+X7\r\nwWj11cU6qpkeexbMoUmTzuXUAGiSBqAjBcTVhh+3mdQP40ioix753/+Xk1ou\r\njgakl20VuzN/LYjUF2GiYQxsDHrQhvhWYlpMCv0Gc1DhJv9GsaQvdORJDjfK\r\nenAQnMDAEe7SSpMp1WdZxAR7JfBMnLHhXS19qoj+heI3Zw2UfETpIF2YeeFm\r\n3nd2tLCyyzChRWDA8xbzaXTx3ssgDYAnD5SxXBPkzHw+JuSkFUMNVBtHETIN\r\n7NFOJ5xKXPECnthzHJmlP4K7BVjS5yUCdAhKCa5z580Y6sfvCMtz3rvRH15E\r\nNAPtwqOgEKQeQK5l1VGE6S/Annek60ipDfaZeBV0RkJ+6alpbiacx22gF8Hb\r\nROgJBypB8h2V57FP0hAr1L0qgupPXT25je7b+J3dcJlIAJc/c1wos0vBEmqc\r\nnfX9sThRkX5d8sH+VcxVSEMQBvxbD18l5VigzcOuZaW65JgslCJ0mEYxeGwE\r\n3s+4eUBrIQItggeHSRpnnOm1dy9HAN7IjZxnqOUENUNxkvw+UqBIBAGkcjNC\r\nzLOCz3L871MYT3Zyr/hVqbtMY+D+iBvk2+iFppU1qE7IB3yZxGTIi+rHQAOW\r\nnQv1WlAVp0V0GDd7ja32nPVcRs4gvXuzbRg=\r\n=2fw9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"mapbox-npm-08","email":"accounts+npmjs-08@mapbox.com"},"directories":{},"maintainers":[{"name":"mapbox-npm-01","email":"accounts+npmjs-01@mapbox.com"},{"name":"mapbox-npm-02","email":"accounts+npmjs-02@mapbox.com"},{"name":"mapbox-npm-07","email":"accounts+npmjs-07@mapbox.com"},{"name":"mapbox-npm-03","email":"accounts+npmjs-03@mapbox.com"},{"name":"mapbox-npm-04","email":"accounts+npmjs-04@mapbox.com"},{"name":"mapbox-npm-09","email":"accounts+npmjs-09@mapbox.com"},{"name":"mapbox-npm-05","email":"accounts+npmjs-05@mapbox.com"},{"name":"mapbox-npm-06","email":"accounts+npmjs-06@mapbox.com"},{"name":"mapbox-npm-08","email":"accounts+npmjs-08@mapbox.com"},{"name":"mapbox-npm-advanced-actions","email":"accounts+npmjs-advanced-actions@mapbox.com"},{"name":"mapbox-npm-ci","email":"accounts+npmjs-npm-ci@mapbox.com"},{"name":"mapbox-npm","email":"accounts+npmjs@mapbox.com"},{"name":"mapbox-admin","email":"accounts@mapbox.com"},{"name":"mapbox-machine-user","email":"accounts+npm-mapbox-machine-user@mapbox.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/secret-shield_1.0.5_1663872616971_0.12407637396864413"},"_hasShrinkwrap":false},"1.0.6":{"name":"@mapbox/secret-shield","version":"1.0.6","description":"Search for secrets in the specified github repo","main":"index.js","scripts":{"test":"tape test/*.test.js | tap-spec","lint":"eslint -c .eslintrc.js *.js **/*.js"},"engines":{"node":">=14"},"bin":{"secret-shield":"bin/secret-shield.js"},"author":{"name":"Mapbox"},"license":"ISC","dependencies":{"acorn":"^8.7.1","command-join":"^3.0.0","command-line-args":"^5.2.1","d3-queue":"^3.0.7","decrypt-kms-env":"^3.0.0","es6-promise":"^4.2.8","esprima":"^4.0.1","fast-fuzzy":"^1.11.1","find-in-files":"^0.5.0","git-clone":"^0.2.0","lodash":"^4.17.21","md5":"^2.3.0","p-queue":"2.4.2","proxyquire":"^2.1.3","rewire":"^6.0.0","rimraf":"^3.0.2","semver":"^7.3.7","shelljs":"^0.8.5","simple-statistics":"^7.7.5","tty-table":"^4.1.5","uuid":"7.0.3","yamljs":"^0.3.0"},"devDependencies":{"@mapbox/cloudfriend":"^5.1.1","@mapbox/dyno":"^1.5.1","@mapbox/watchbot":"^4.7.1","@octokit/rest":"^18.12.0","aws-sdk":"^2.1129.0","eslint":"^8.14.0","got":"^12.0.4","sinon":"14.0.0","tap-spec":"^5.0.0","tape":"^5.5.3"},"gitHead":"e510153b5b1a15957af4776592e15a428161ef11","_id":"@mapbox/secret-shield@1.0.6","_nodeVersion":"16.16.0","_npmVersion":"8.19.3","dist":{"integrity":"sha512-E0fjdwrWeDk5iv8FxjP4f+OsNSOUvwTz3OWrjF8lp6n/RBaDEY4BPCauMeZyEsVGnCmy7+b1ef5niyUeV9Xccw==","shasum":"8cfd95a3952d61bdfff1ecbd4e993509b80a1f7d","tarball":"https://registry.npmjs.org/@mapbox/secret-shield/-/secret-shield-1.0.6.tgz","fileCount":79,"unpackedSize":695777,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHE8dnUt92uRxUcBmK0LmOH4lNr+90qxSU8d2sA+XpAmAiEAyrdxW/v7p2cbk+G4asDwL+xvLKIPavPh1rc9BTKddf0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJja76GACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrVsg//fTBeVKIZULUR+ZqRpwM9r0/uJyIMaPSk39M3bBvJ4u7rFKXB\r\nESIOGa5SY8680Hjud/Djpu3gldLPUQz2/MJk/YwDsdTKm3pUmdkBSZIKpB0G\r\nO6u5xflExXMvwlzgo2AJ0r+VvPmswDQRnF2ma/mg+IluvVNF+UEft28bfhOd\r\n9BDLRyBqAmsqwwN/sjP76XknlgkECDQK/T2JxlSgTp0sjNDyRZfR4fBoT15I\r\niApyl65AqUeIZ6k8jBeEKWhnQ9mDACYdMitVB8thhz4oszCcPu0mJ8pjmoiO\r\ng5eKT5RSZpOz3SOshSCVBhGuswqd7j1QFBGHcDEat8Nbfkjrnacpyw7ktOQ7\r\nNe2eFnuGPYfyygX4l7xF/r4UppwCHNOzT2d8uu1mKvW8Nqb/5D/Z38Tb8XPk\r\n9INtaw9o5PoxghAZYW2VM8vqUaFJyiaWVtk6Z1uGW+LVIj8OCl4iM2K8OzBu\r\n/yzrKFgxjDlFq6MKenuUOeFj+hjtgROd+HlQfGiql1Evbm+AnesSaq141AjQ\r\nHkEIYHn0ZUJOa5p1ewGXbnv7BEpeGFNKp2Mv3tLeSLDp99p1gKMhuwOWH09Y\r\n6DWnCOF6bt35QeaIOvaaAR//O7b1qo5ePrXquCzK7zrZGZkYuCJ9ZNVQVp6c\r\nl9gqcEe9FrNiAW9Q0cSQLKbE1j56AK29xtk=\r\n=8k/G\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"mapbox-npm-04","email":"accounts+npmjs-04@mapbox.com"},"directories":{},"maintainers":[{"name":"mapbox-npm-01","email":"accounts+npmjs-01@mapbox.com"},{"name":"mapbox-npm-02","email":"accounts+npmjs-02@mapbox.com"},{"name":"mapbox-npm-07","email":"accounts+npmjs-07@mapbox.com"},{"name":"mapbox-npm-03","email":"accounts+npmjs-03@mapbox.com"},{"name":"mapbox-npm-04","email":"accounts+npmjs-04@mapbox.com"},{"name":"mapbox-npm-09","email":"accounts+npmjs-09@mapbox.com"},{"name":"mapbox-npm-05","email":"accounts+npmjs-05@mapbox.com"},{"name":"mapbox-npm-06","email":"accounts+npmjs-06@mapbox.com"},{"name":"mapbox-npm-08","email":"accounts+npmjs-08@mapbox.com"},{"name":"mapbox-npm-advanced-actions","email":"accounts+npmjs-advanced-actions@mapbox.com"},{"name":"mapbox-npm-ci","email":"accounts+npmjs-npm-ci@mapbox.com"},{"name":"mapbox-npm","email":"accounts+npmjs@mapbox.com"},{"name":"mapbox-admin","email":"accounts@mapbox.com"},{"name":"mapbox-machine-user","email":"accounts+npm-mapbox-machine-user@mapbox.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/secret-shield_1.0.6_1668005510515_0.21150941363280706"},"_hasShrinkwrap":false}},"maintainers":[{"email":"yannick.meeus+npm+production+ci@mapbox.com","name":"mbx-npm-ci-production"},{"email":"yannick.meeus+npm+staging+ci@mapbox.com","name":"mbx-npm-ci-staging"},{"email":"yannick.meeus+npm+prod+advanced+actions@mapbox.com","name":"mbx-npm-advanced-actions-production"},{"email":"yannick.meeus+npm+staging+advanced+actions@mapbox.com","name":"mbx-npm-advanced-actions-staging"},{"email":"yannick.meeus+npm+prod+09@mapbox.com","name":"mbx-npm-09-production"},{"email":"yannick.meeus+npm+prod+08@mapbox.com","name":"mbx-npm-08-production"},{"email":"yannick.meeus+npm+prod+07@mapbox.com","name":"mbx-npm-07-production"},{"email":"yannick.meeus+npm+prod+06@mapbox.com","name":"mbx-npm-06-production"},{"email":"yannick.meeus+npm+prod+05@mapbox.com","name":"mbx-npm-05-production"},{"email":"yannick.meeus+npm+prod+04@mapbox.com","name":"mbx-npm-04-production"},{"email":"yannick.meeus+npm+prod+03@mapbox.com","name":"mbx-npm-03-production"},{"email":"yannick.meeus+npm+prod+02@mapbox.com","name":"mbx-npm-02-production"},{"email":"yannick.meeus+npm+prod+01@mapbox.com","name":"mbx-npm-01-production"},{"email":"yannick.meeus@mapbox.com","name":"mbx-npm-02-staging"},{"email":"accounts+npmjs-01@mapbox.com","name":"mapbox-npm-01"},{"email":"accounts+npmjs-02@mapbox.com","name":"mapbox-npm-02"},{"email":"accounts+npmjs-07@mapbox.com","name":"mapbox-npm-07"},{"email":"accounts+npmjs-03@mapbox.com","name":"mapbox-npm-03"},{"email":"accounts+npmjs-04@mapbox.com","name":"mapbox-npm-04"},{"email":"accounts+npmjs-09@mapbox.com","name":"mapbox-npm-09"},{"email":"accounts+npmjs-05@mapbox.com","name":"mapbox-npm-05"},{"email":"accounts+npmjs-06@mapbox.com","name":"mapbox-npm-06"},{"email":"accounts+npmjs-08@mapbox.com","name":"mapbox-npm-08"},{"email":"accounts+npmjs-advanced-actions@mapbox.com","name":"mapbox-npm-advanced-actions"},{"email":"accounts+npmjs-npm-ci@mapbox.com","name":"mapbox-npm-ci"},{"email":"accounts+npmjs@mapbox.com","name":"mapbox-npm"},{"email":"accounts@mapbox.com","name":"mapbox-admin"},{"email":"accounts+npm-mapbox-machine-user@mapbox.com","name":"mapbox-machine-user"}],"description":"Search for secrets in the specified github repo","author":{"name":"Mapbox"},"license":"ISC","readme":"# secret-shield [![Build Status](https://travis-ci.com/mapbox/secret-shield.svg?token=xWoUHsqdcvsQdxzwqjXH&branch=main)](https://travis-ci.com/mapbox/secret-shield)\n\n<!-- MarkdownTOC -->\n\n1. [🚨 Are you being blocked from committing? 🚨](#%F0%9F%9A%A8-are-you-being-blocked-from-committing-%F0%9F%9A%A8)\n1. [About secret-shield](#about-secret-shield)\n1. [Install](#install)\n1. [Requirements](#requirements)\n    1. [Quick Install and setup](#quick-install-and-setup)\n    1. [Manual Install](#manual-install)\n    1. [Uninstalling](#uninstalling)\n1. [Using secret-shield](#using-secret-shield)\n    1. [Setting up automated searching](#setting-up-automated-searching)\n    1. [Manually searching](#manually-searching)\n    1. [Additional functionality](#additional-functionality)\n1. [FAQ:](#faq)\n    1. [Does secret-shield auto-update?](#does-secret-shield-auto-update)\n    1. [Why secret-shield?](#why-secret-shield)\n    1. [What does it search for, exactly?](#what-does-it-search-for-exactly)\n    1. [It says it found a secret but it’s not, what do I do?](#it-says-it-found-a-secret-but-it%E2%80%99s-not-what-do-i-do)\n    1. [It says it found a secret and it actually is a secret, what do I do?](#it-says-it-found-a-secret-and-it-actually-is-a-secret-what-do-i-do)\n    1. [Does it work with my git client?](#does-it-work-with-my-git-client)\n    1. [I already have pre-commit hooks for something else, will secret-shield work with them?](#i-already-have-pre-commit-hooks-for-something-else-will-secret-shield-work-with-them)\n        1. [Husky + lint-staged integration](#husky--lint-staged-integration)\n\n<!-- /MarkdownTOC -->\n\n<a id=\"%F0%9F%9A%A8-are-you-being-blocked-from-committing-%F0%9F%9A%A8\"></a>\n## 🚨 Are you being blocked from committing? 🚨\n\nSome repositories [require secret-shield](./docs/enabledBadge.md) to commit to them. If you don't have secret-shield you'll be blocked from committing to those repos\n\nIf secret-shield is installed on your machine, [read this](https://github.com/mapbox/secret-shield/blob/main/docs/commonIssues.md) for common issues with secret-shield and how to fix them.\n\n<a id=\"about-secret-shield\"></a>\n## About secret-shield\n\n`secret-shield` is a convenient way to protect against inadvertently committing potential secrets to GitHub. It can be set up to automatically run before each commit (if it catches something, it will stop the commit and ask you to review the findings), or you can manually run it from the command line.\n\n![Secret-shield in action](https://github.com/mapbox/secret-shield/raw/assets/shield.gif)\n\n**Please note:** secret-shield will now be required when working with certain repositories. [Learn more](./docs/enabledBadge.md).\n\n**If you want to add secret-shield to your repository**, [take a look here](./docs/enabledRepositories.md).\n\n<a id=\"install\"></a>\n## Install\n\n<a id=\"requirements\"></a>\n## Requirements\n\n`secret-shield` is a Node project [tested with Node 10 & 12](https://github.com/mapbox/secret-shield/blob/main/.travis.yml)\n\n`secret-shield` requires `npm >= 6` to install globally. Previous versions of npm will not correcly install the required dependencies.\n\n<a id=\"quick-install-and-setup\"></a>\n### Quick Install and setup\n\n```\nnpm install -g @mapbox/secret-shield\n```\n\nYou still need to [set it up](#setting-up-automated-searching). Easiest way: `secret-shield --add-hooks global`.\n\n<a id=\"manual-install\"></a>\n### Manual Install\n\nClone this repository, then from inside it, run:\n\n```\nnpm install\nnpm link\n```\n\nTests are available using `npm test`.\n\nYou still need to [set it up](#setting-up-automated-searching). Easiest way: `secret-shield --add-hooks global`.\n\n<a id=\"using-secret-shield\"></a>\n\n### Uninstalling\n\nTo uninstall secret-shield:\n1. make sure that you don't have any global hooks configured for secret-shield: `secret-shield --remove-hooks global`\n2. uninstall secret-shield normally (if you installed using npm, you can run `npm remove -g @mapbox/secret-shield`)\n\n## Using secret-shield\n\nYou can set up `secret-shield` to automatically search for secrets before each commit, or manually run it from anywhere.\n\n<a id=\"setting-up-automated-searching\"></a>\n### Setting up automated searching\n\n`secret-shield` uses pre-commit hooks to run before each commit and check for secrets only in whatever changes you've made. You can create these hooks either globally or on a per-repository basis.\n* To create a global pre-commit hook that will run on all repositories, run `secret-shield --add-hooks global` (to remove, use `--remove-hooks global`)\n* To create pre-commit hooks only for your current repository, run `secret-shield --add-hooks local` (to remove, use `--remove-hooks local`). Note that, if working with others, it's almost always a better idea to [install secret-shield directly in your repository](./docs/enabledRepositories.md) so that everyone who works on it uses secret-shield.\n\nIf a potential secret is found, secret-shield will abort the commit and provide you with its findings. After reviewing the findings, you can either go back and change your files or force the commit through without any checks by running `git commit` with the `--no-verify` flag.\n\n<a id=\"manually-searching\"></a>\n### Manually searching\n\nYou can manually use `secret-shield` to search through:\n* Files: `secret-shield <--file|-f> <file>`\n* Directories: `secret-shield <--directory|-d> <directory>`\n* Repositories: `secret-shield <--repository|-r> <repository> [branch]`\n* Strings: `secret-shield <--string|-s> <string>`\n* CloudFormation template files: automatically detected\n\nUse `<--redact|-R> [number]` if you need to redact potentially sensitive information: output will be truncated to the specified number of characters.\n\n<a id=\"additional-functionality\"></a>\n### Additional functionality\n\n* You can [change the rules used by `secret-shield`](./docs/ruleManipulation.md) and also [write your own rules](./docs/writingRules.md).\n* You can [specify advanced output (such as JSON output) and redaction rules](./docs/outputManipulation.md).\n* Secret-shield also supports some [basic batch processing](./docs/batchProcessing.md). (Work in progress)\n\n<a id=\"faq\"></a>\n# FAQ:\n\n<a id=\"does-secret-shield-auto-update\"></a>\n## Does secret-shield auto-update?\n\nYes, secret-shield will automatically check for updates on average once in every 20 runs as a pre-commit hook.\n\n<a id=\"why-secret-shield\"></a>\n## Why secret-shield?\n\nCredential leaks are frequently a problem in any organization or team. Secret-shield aims to nullify the impact of a credential leak by blocking it *before the secret has a chance to get out in the first place*.\n\nWhen combined with documented best practices for handling secrets, secret-shield can dramatically reduce the probability of a leaked secret. Secret-shield can find already-leaked secrets much faster than searching by hand -- when combined with a robust incident response framework, this can significantly reduce the impact of a credential leak.\n\nSecurity researchers can use secret-shield to find and report leaked secrets to affected teams or organizations.\n\n<a id=\"what-does-it-search-for-exactly\"></a>\n## What does it search for, exactly?\n\nBy default, secret-shield performs a minimal search: AWS client IDs, Mapbox secure keys, Slack tokens, and GitHub tokens.\n\nIf you [perform more advanced searches](https://github.com/mapbox/secret-shield/blob/main/docs/ruleManipulation.md#alternate-ruleset), secret-shield can look for more things, such as AWS secret IDs, “don’t commit” messages, and high-entropy strings.\n\n<a id=\"it-says-it-found-a-secret-but-it%E2%80%99s-not-what-do-i-do\"></a>\n## It says it found a secret but it’s not, what do I do?\n\nIf it ran automatically before a commit, simply commit with the `--no-verify` flag. It won’t prompt you about those findings again, unless you change something in those lines.\n\nIf you ran it manually, you can ignore the findings.\n\n<a id=\"it-says-it-found-a-secret-and-it-actually-is-a-secret-what-do-i-do\"></a>\n## It says it found a secret and it actually is a secret, what do I do?\n\nIf it ran automatically before a commit and the secret wasn’t there before, simply go back and remove the secret: it didn’t commit it, so you’re safe.\n\nIf the secret was there before (so it’s already been committed), or if you ran it manually and it found a secret that’s already been committed, the secret should be considered compromised -- follow your company or project's procedures for handling leaked secrets.\n\n<a id=\"does-it-work-with-my-git-client\"></a>\n## Does it work with my git client?\n\nSecret-shield uses pre-commit hooks; some clients support them, others just force commits through regardless. You should check your client’s documentation on whether it supports pre-commit hooks.\n\n<a id=\"i-already-have-pre-commit-hooks-for-something-else-will-secret-shield-work-with-them\"></a>\n## I already have pre-commit hooks for something else, will secret-shield work with them?\n\nYes! Secret-shield will automatically detect any local hooks that you have, e.g. husky, and run them instead. If you want to run secret-shield on that repository, you should add it to those local hooks. [Take a look here.](https://github.com/mapbox/secret-shield/blob/main/docs/enabledRepositories.md)\n\n<a id=\"husky--lint-staged-integration\"></a>\n### Husky + lint-staged integration\n\nYou can use secret-shield with [husky](https://github.com/typicode/husky) and [lint-staged](https://github.com/okonet/lint-staged) by adding secret-shield as an npm dependency in your package.json and using the following configuration\n\n```json\n  \"husky\": {\n    \"hooks\": {\n      \"pre-commit\": \"lint-staged && secret-shield --check-and-run\"\n    }\n  },\n  \"lint-staged\": {\n    \"*\": [\n      \"command2\",\n      \"command2\"\n    ]\n  }\n```\n\nIf you are using an old version of husky\n\n```json\n  \"scripts\": {\n    \"precommit\": \"lint-staged && secret-shield --check-and-run\"\n  },\n  \"lint-staged\": {\n    \"*\": [\n      \"command2\",\n      \"command2\"\n    ]\n  }\n```\n","readmeFilename":"README.md"}