About this project
ggshield is a command-line application from GitGuardian for detecting hardcoded secrets in your code. It runs locally or in CI and covers more than 500 secret types, using GitGuardian's public API through the py-gitguardian client to scan files and other text content.
Privacy note from the README: only metadata such as call time, request size and scan mode is stored from scans, so secrets are not shown on your dashboard and files and secrets are not stored.
Installation options are broad: a recommended install script for Linux/macOS and Windows PowerShell, Homebrew on macOS, a standalone .pkg, Deb and RPM packages via Cloudsmith, Chocolatey and MSI installers on Windows, a standalone .zip, and PyPI via pipx (recommended) or pip. Standalone packages avoid needing Python installed but require manual updates.
Setup requires authenticating against GitGuardian servers. The `ggshield auth login` command provisions a personal access token and configures it locally; alternatively you can create a token manually and set the `GITGUARDIAN_API_KEY` environment variable. A legacy `.gitguardian.yaml` configuration can be migrated with `ggshield config migrate`, which keeps a `.old` backup.
Scanning targets include files (`ggshield secret scan path -r .`), repositories (`ggshield secret scan repo .`), Docker images (requires the docker command) and PyPI packages (requires pip). The README points to `ggshield secret scan --help` for the full list.
Integrations cover CI/CD workflows and Git hooks (pre-commit, pre-push, pre-receive) to catch secrets before they reach version control. Notably, ggshield can also scan interactions with AI coding assistants in real time and block actions containing secrets before they execute; supported tools listed are Cursor, Claude Code, Copilot Chat, Codex and Mistral Vibe 2.21+. Hooks are installed with `ggshield install`.
Output behavior: exit code 0 when no secrets are found. When a secret is found, the tool reports the filename and shows a patch indicating the secret's position, with long lines truncated unless verbose mode (`-v` or `--verbose`) is used.
The README also lists related open source projects (truffleHog, gitleaks, gitrob, git-hound, AWS git-secrets, detect-secrets) and states the project is MIT licensed. A macOS note warns that upgrading to 1.54.0 triggers a Keychain prompt for `ggshield-py`, a second binary that reads the saved token as part of performance improvements; users should click Always Allow.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.