START LOCALLY

From checkout to first scan.

Python 3.11 or newer. Install the scanner from this repository; no PyPI release is claimed.

Install and scan.

git clone https://github.com/yassineeljal/SecretSense.git
cd SecretSense
python3 -m venv .venv
source .venv/bin/activate
python -m pip install -e ./core
secretsense scan ./my-project

These activation commands target macOS/Linux shells. On Windows PowerShell use .venv\Scripts\Activate.ps1. Replace ./my-project with your local target. Exit codes are 0 for no candidates, 1 for candidates, and 2 for invalid input or incomplete work.

Choose a report.

secretsense scan ./my-project --format json
secretsense scan ./my-project --format html > ../scan-report.html
secretsense scan ./my-project --format sarif > ../scan-report.sarif

Keep report files outside the scanned tree. All formats mask detected values; CLI paths and partial values remain sensitive.

CLI, trusted model loading, and bounded history

Use it in GitHub Actions.

The repository supplies a reusable Linux Action with SARIF output. Pin its reviewed full commit SHA in another repository. In this repository, use the local Action after checkout:

- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803
- uses: ./
  with:
    path: .
    fail-on-findings: "true"

The Action scans locally. SARIF upload is a separate caller decision. Incomplete scans always fail.

Action inputs, outputs, and integration guide

Run the browser demo.

Install the API extra, start one loopback worker, then build and start the site. The setup guide includes exact commands and limits. Public portfolio builds disable scan input.

Local API and browser setup