Scan your GitHub Gists for secrets, high-entropy tokens, regex patterns, and terms.
Built with Typescript & Deno.
Important
This project is in early alpha. It can be reliably cloned and run with the "make run" command, on linux systems or those with Makefile support. We are currently iterating on improving the pagination features and speed.
deno install --allow-net --allow-env -n gist-scan https://jsr.io/@softdist/gist-scanner@v0.1.2gist-scan [OPTIONS]| Option | Description |
|---|---|
-t, --term |
Search term(s) to match in gists (filename, description, and content). |
-r, --regex |
Regex pattern(s) to match in gists. |
-s, --secrets |
Scan for high-entropy secrets (GitHub tokens, JWTs, API keys, hashes, etc.). |
-d, --delete |
Delete matched gists. |
-y, --yes |
Auto-confirm deletion without prompting for each gist. |
-h, --help |
Display this help message with usage examples. |
gist-scan --term "password"gist-scan --regex "AKIA[0-9A-Z]{16}"gist-scan --secretsgist-scan --term "password" --deletegist-scan --term "password" --delete --yesgist-scan --regex "my-api-key-\d+" --secretsGH_SCAN_TOKEN: GitHub Personal Access Token (PAT) used for authenticated API access to list and delete Gists.
Example:
export GH_SCAN_TOKEN=your_github_pat_hereHow to Publish to jsr.io
deno check mod.tsjsr publish --version v0.1.0deno install --allow-net --allow-env -n gist-scan https://jsr.io/@softdist/gist-scanner@0.1.0---
title: PR workflow
---
graph TD;
terms-->gist_search;
terms-->entropy_regex;
terms-->single_search;
gist_search-->content;
gist_search-->title;
delete-->dry_run;
delete-->auto_delete;
MIT License © 2024 Lyns A.