Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos. Gitleaks aims to be the easy-to-use, all-in-one solution for finding secrets, past or present, in your code.
Features:
- Scan for commited secrets
- Scan for unstaged secrets as part of shifting security left
- Scan directories and files
*Available Github Action - Custom rules via toml configuration
- High performance using go-git
- JSON, SARIF, and CSV reporting
- Private repo scans using key or password based authentication
Fast jede Webanwendung sorgt selbst für das sichere Speichern von Zugangsdaten. Vault ist eine Alternative, die in Entwicklungsumgebungen ohne großen Administrationsaufwand funktioniert.
Nahezu jede Webanwendung enthält Geheimnisse, etwa in Form von Zugangsdaten zu Drittsystemen wie Datenbanken oder Fileshares. Jede Anwendung steht damit vor der Herausforderung, sie sicher zu speichern. Mit dem Projekt Vault von Hashicorp steht hierfür [1] ein umfangreiches und erweiterbares Open-Source-Tool zur Verwaltung von eben jenen Geheimnissen und zum Schutz der darin gespeicherten Daten zur Verfügung ("Manage Secrets and Protect Sensitive Data"). Im Dezember 2018 hat das Projekt Version 1.0 erreicht und liegt damit erstmals in einer stabilen Edition vor. Höchste Zeit für die ersten Schritte mit Vault in einer Entwicklungsumgebung.
HashiCorp Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Vault handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more.