Developer-focused secret scanner for GitHub Actions, local CLI, and a SQLite-backed dashboard.
- Node.js 20+
- npm 11+
npm install
npm run db:generate
npm test
npm run devOpen http://localhost:3000, choose a repository .zip, and run a scan. Uploads
are limited to 20 MB, extracted into a temporary directory, and deleted after the
masked findings have been saved.
Quality checks:
npm run typecheck
npm run lint
npm run format:check
npm run build@sentinel/scanner recursively scans text files without executing repository code.
It ignores dependency/build directories, symlinks, binary files, and files over 1 MB by
default. Findings contain masked values only.
import { scanDirectory } from "@sentinel/scanner";
const result = await scanDirectory("./project");Current rules cover AWS, GitHub, Slack, and Google keys; private keys; credentialed
database URLs; hardcoded passwords; JWTs; generic API keys; sensitive .env values;
and suspicious high-entropy strings.
Build the workspace, then scan a local directory:
npm run build
node cli/dist/index.js scan ./my-project
node cli/dist/index.js scan ./my-project --jsonScan pull requests and main with the repository action:
name: Sentinel
on:
pull_request:
push:
branches: [main]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: <owner>/sentinel@v1
with:
path: .
fail-on: nonepath defaults to .. fail-on accepts none, low, medium, high, or
critical; none reports findings without failing CI. Outputs are findings
(masked JSON), files-scanned, and highest-severity. The action scans only the
checked-out workspace and creates file/line annotations plus a job summary.
Use the CLI for the same local scan behavior. Review findings before enabling a gate: pattern scanners can flag test values, examples, or non-secret identifiers. Never unmask a finding in logs. If a finding is real, revoke/rotate the credential, remove it from history where appropriate, and replace it through a secret manager.
Release immutable tags such as v1.2.3, then move the major tag (v1) to the
latest compatible release so workflows can use @v1.
SQLite is the local MVP default. Create or update the schema with:
npm run db:generate
npm run db:migrate -- --name <migration-name>Sentinel reduces common secret-exposure risks but cannot prove that a repository is secure. Treat every finding as sensitive, rotate exposed credentials, and use a dedicated secret manager. Never scan untrusted code with tools that execute it.
Uploaded archives are validated before extraction: traversal paths and symlinks are rejected; archive entry, per-file, and expanded-size limits prevent resource abuse. Sentinel only reads text files and never stores uploaded source code.
See THREAT_MODEL.md for the upload boundary and deployment risks.
apps/web— Next.js applicationpackages/scanner— framework-independent scannercli— local repository scanner CLI
The scanner, CLI, dashboard foundation, and reusable GitHub Action are available.