LinuxCommandLibrary
GitHubF-DroidGoogle Play Store

ripsecrets

Fast local scanner to stop secrets entering git commits

TLDR

Scan the current directory for secrets
$ ripsecrets
copy
Scan specific files (e.g. staged changes)
$ ripsecrets --strict-ignore $(git diff --cached --name-only --diff-filter=ACM)
copy
Install as a git pre-commit hook
$ ripsecrets --install-pre-commit
copy

SYNOPSIS

ripsecrets [*options*] [*path*...]

DESCRIPTION

ripsecrets searches source files for high-entropy strings and known secret patterns to prevent accidental commits. It is designed for pre-commit speed: local-only (no cloud verification), low false-positive rate relative to naive regex tools, and a single static binary.

PARAMETERS

*path*...

Files or directories to scan (default: recursive from cwd).
--install-pre-commit
Install a git pre-commit hook that runs ripsecrets.
--strict-ignore
Honor ignore rules strictly when scanning explicit file lists (typical with git diff --cached).
Additional flags control allowlists and output—see ripsecrets --help.

INSTALL

brew install ripsecrets
copy
nix profile install nixpkgs#ripsecrets
copy

CAVEATS

Local pattern matching cannot prove a string is a live credential; it also cannot catch every secret type. Use with commit hooks and complementary scanners for defense in depth. Never commit real secrets “just for testing.”

SEE ALSO

git(1), gitleaks(1), trufflehog(1)

RESOURCES

Copied to clipboard
Kai