infisical scan, that finds leaked secrets in a Git repository’s history, in a directory, or in changes you haven’t committed yet. It uses the same rules and configuration format as scans of connected repositories, but it runs on your machine or in a CI job and doesn’t need an Infisical login. Its findings stay local: the CLI prints them, or writes them to a report file if you ask for one.
Prerequisites
- The Infisical CLI installed
- Git installed, if you’re scanning a Git repository
Scan a repository or a directory
To scan the full history of the Git repository you’re in, run:--log-opts, such as --log-opts="--all commitA..commitB". To scan the current files without reading Git history, add --no-git and point --source at a directory or a file:
1, which fails a CI job. To write the findings to a file, add --report-path, and pick a format with --report-format: json (the default), csv, sarif, or junit. The infisical scan reference lists every flag.
Scan changes before you commit
infisical scan git-changes scans only the changes in your working tree, so you can catch a secret before it’s in a commit. Add --staged to scan what your next commit will contain:
Install the pre-commit hook
To run that scan before every commit, run this command in your repository:.git/hooks/pre-commit, and Git then blocks any commit the scan finds a secret in. To turn the hook off in a repository, run git config hooks.infisical-scan false.
Use a Git hook manager
If a hook manager such as Husky runs your Git hooks, don’t useinfisical scan install. Hook managers point Git’s core.hooksPath setting at their own folder, and the install command offers to change that setting back to .git/hooks, which stops the hook manager’s hooks from running. Instead, add the scan to the hook manager’s pre-commit script, such as .husky/pre-commit:
Ignore findings you’ve already reviewed
A scan can flag a value you’ve decided is safe to commit, such as a test credential. You can ignore one line, ignore specific findings, or ignore every finding that already exists in the repository.Ignore one line
To ignore a secret on one line of code, add abetterleaks:allow comment at the end of the line:
example.js
gitleaks:allow, so existing gitleaks:allow comments keep working.
Ignore specific findings
Each finding has a fingerprint, which you can find in theFingerprint field of a JSON report. To ignore findings, list their fingerprints in a .infisicalignore file, one per line, in the directory you scan (the --source directory, which is the current directory by default):
.infisicalignore
<commit>:<file>:<rule>:<line>, and ignores the finding in that commit only. To ignore a finding in every commit, leave out the commit and write <file>:<rule>:<line>, which is also the form that scans without Git history report.
Ignore every existing finding with a baseline
If you start scanning a repository that already has a long history, you can record every current finding in a baseline and have later scans report only new ones. First, write a JSON report of the current findings:--baseline-path:
findings.json then contains only the findings that aren’t in baseline.json. The baseline must be a report in the default json format. infisical scan git-changes doesn’t use a baseline.
Customize the scan rules
By default, the scanner uses its built-in rules, which cover the credential formats of hundreds of services. To add your own rules or skip paths, create a configuration file named.infisical-scan.toml in the directory you scan. To use a file with a different name or location, pass it with --config or set INFISICAL_SCAN_CONFIG.
A configuration file replaces the built-in rules unless it extends them. Set useDefault = true in the [extend] table to keep the built-in rules and add yours to them:
.infisical-scan.toml
[extend]:useDefault = truekeeps the built-in rules,pathextends another configuration file instead (relative to the directory you run the CLI in), anddisabledRulesturns off built-in rules by ID[[rules]]: a detection rule with a uniqueid, a Go regular expression inregex, andkeywordsthat a line must contain before the regular expression runs on itentropyandsecretGroupin a rule: the minimum randomness a match needs, and the regular expression group that holds the secret[[allowlists]]: matches to skip, by filepaths,regexes,stopwordsfound in the secret, orcommits
id as a built-in rule, the fields you set replace the built-in rule’s fields. The built-in rules are in the CLI’s default configuration, which is also a reference for every field a rule can use.
Next steps
Usage
Scan connected GitHub, GitLab, and Bitbucket repositories from Infisical.
infisical scan
See every flag of the scan commands.