Skip to main content
The Infisical CLI includes a secret scanner, infisical scan, that finds leaked secrets in a Git repository’s history, in a directory, or in changes you haven’t committed yet. It uses the same rules and configuration format as scans of connected repositories, but it runs on your machine or in a CI job and doesn’t need an Infisical login. Its findings stay local: the CLI prints them, or writes them to a report file if you ask for one.

Prerequisites

  • The Infisical CLI installed
  • Git installed, if you’re scanning a Git repository

Scan a repository or a directory

To scan the full history of the Git repository you’re in, run:
The scan reads every commit on every branch. To scan a range of commits instead, pass Git log options with --log-opts, such as --log-opts="--all commitA..commitB". To scan the current files without reading Git history, add --no-git and point --source at a directory or a file:
If the scan finds a secret, the command exits with code 1, which fails a CI job. To write the findings to a file, add --report-path, and pick a format with --report-format: json (the default), csv, sarif, or junit. The infisical scan reference lists every flag.

Scan changes before you commit

infisical scan git-changes scans only the changes in your working tree, so you can catch a secret before it’s in a commit. Add --staged to scan what your next commit will contain:

Install the pre-commit hook

To run that scan before every commit, run this command in your repository:
The CLI adds the hook to .git/hooks/pre-commit, and Git then blocks any commit the scan finds a secret in. To turn the hook off in a repository, run git config hooks.infisical-scan false.

Use a Git hook manager

If a hook manager such as Husky runs your Git hooks, don’t use infisical scan install. Hook managers point Git’s core.hooksPath setting at their own folder, and the install command offers to change that setting back to .git/hooks, which stops the hook manager’s hooks from running. Instead, add the scan to the hook manager’s pre-commit script, such as .husky/pre-commit:

Ignore findings you’ve already reviewed

A scan can flag a value you’ve decided is safe to commit, such as a test credential. You can ignore one line, ignore specific findings, or ignore every finding that already exists in the repository.

Ignore one line

To ignore a secret on one line of code, add a betterleaks:allow comment at the end of the line:
example.js
The scanner also accepts gitleaks:allow, so existing gitleaks:allow comments keep working.

Ignore specific findings

Each finding has a fingerprint, which you can find in the Fingerprint field of a JSON report. To ignore findings, list their fingerprints in a .infisicalignore file, one per line, in the directory you scan (the --source directory, which is the current directory by default):
.infisicalignore
A fingerprint from a Git scan has the form <commit>:<file>:<rule>:<line>, and ignores the finding in that commit only. To ignore a finding in every commit, leave out the commit and write <file>:<rule>:<line>, which is also the form that scans without Git history report.

Ignore every existing finding with a baseline

If you start scanning a repository that already has a long history, you can record every current finding in a baseline and have later scans report only new ones. First, write a JSON report of the current findings:
Then pass that report to later scans with --baseline-path:
findings.json then contains only the findings that aren’t in baseline.json. The baseline must be a report in the default json format. infisical scan git-changes doesn’t use a baseline.

Customize the scan rules

By default, the scanner uses its built-in rules, which cover the credential formats of hundreds of services. To add your own rules or skip paths, create a configuration file named .infisical-scan.toml in the directory you scan. To use a file with a different name or location, pass it with --config or set INFISICAL_SCAN_CONFIG. A configuration file replaces the built-in rules unless it extends them. Set useDefault = true in the [extend] table to keep the built-in rules and add yours to them:
.infisical-scan.toml
  • [extend]: useDefault = true keeps the built-in rules, path extends another configuration file instead (relative to the directory you run the CLI in), and disabledRules turns off built-in rules by ID
  • [[rules]]: a detection rule with a unique id, a Go regular expression in regex, and keywords that a line must contain before the regular expression runs on it
  • entropy and secretGroup in a rule: the minimum randomness a match needs, and the regular expression group that holds the secret
  • [[allowlists]]: matches to skip, by file paths, regexes, stopwords found in the secret, or commits
If a rule in your file has the same id as a built-in rule, the fields you set replace the built-in rule’s fields. The built-in rules are in the CLI’s default configuration, which is also a reference for every field a rule can use.

Next steps

Usage

Scan connected GitHub, GitLab, and Bitbucket repositories from Infisical.

infisical scan

See every flag of the scan commands.