bc-detect-secrets
Tool for detecting secrets in the codebase
Decision gist · record as of 2026-08-14
Yes. Active maintenance, no known vulnerabilities, low install friction, and permissive licensing make it a practical choice for teams needing to prevent secret leaks. The baseline-first approach is well-suited to large legacy codebases where immediate remediation is infeasible. Install if you need systematic secret detection in git workflows; skip if your codebase is already fully credential-free and you only need occasional ad-hoc scanning.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires git repository context for diff-based scanning; full-file scanning available with --all-files flag but intended for initial baseline creation.
- Low install friction with three lightweight runtime dependencies (pyyaml, requests, unidiff).
- Active maintenance as of 2026-08-13 with recent release.
License · maintenance · safety
Apache License 2.0 (permissive) — Apache License 2.0 (permissive) allows use in commercial and private projects with minimal restrictions; you must include a copy of the license and note material changes.
last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 8 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,525,004 downloads/mo, #2,080 on PyPI
Alternatives
Verify before relying
pip install bc-detect-secrets
# Create baseline of current secrets
detect-secrets scan > .secrets.baseline
# Use in git hook to block new secrets
git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline- Accuracy of the heuristic regex patterns and entropy checks against real-world secret types
- Performance impact when scanning large repositories or high-frequency pre-commit usage
- Customization depth available for organization-specific secret patterns beyond built-in plugins
What it is and what it does
bc-detect-secrets is a secret-detection tool designed for enterprise use, scanning codebases to find hardcoded credentials, API keys, and tokens. Unlike simple pattern matchers, it uses a baseline approach: you create a snapshot of secrets currently in your repository, then the tool prevents new secrets from being committed without explicitly bypassing the check. It runs on git diffs rather than full repository scans, reducing overhead.
The package includes multiple detection plugins and integrates with git hooks and pre-commit workflows. It's maintained by Bridgecrew as a fork of the original Yelp detect-secrets project and depends on pyyaml, requests, and unidiff for configuration, HTTP operations, and diff parsing.
Use it for
- Prevent accidental commits of API keys and database credentials in development workflows via pre-commit hooks
- Create and maintain a baseline of known secrets in legacy codebases while blocking new ones from entering
- Audit existing repositories to identify and catalog secrets for rotation and migration to secure vaults
- Integrate secret detection into CI/CD pipelines to catch credentials before they reach shared branches
- Customize detection rules for organization-specific secret patterns and reduce false positives through filtering
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Active maintenance, no known vulnerabilities, low install friction, and permissive licensing make it a practical choice for teams needing to prevent secret leaks. The baseline-first approach is well-suited to large legacy codebases where immediate remediation is infeasible. Install if you need systematic secret detection in git workflows; skip if your codebase is already fully credential-free and you only need occasional ad-hoc scanning.
Install
bc-detect-secrets on PyPI
Before you install
Low install friction with three lightweight runtime dependencies (pyyaml, requests, unidiff). Active maintenance as of 2026-08-13 with recent release. Supports Python 3.8 through 3.13.
Requires git repository context for diff-based scanning; full-file scanning available with --all-files flag but intended for initial baseline creation.
License in practice
Apache License 2.0 (permissive) allows use in commercial and private projects with minimal restrictions; you must include a copy of the license and note material changes.
Quickstart
pip install bc-detect-secrets
# Create baseline of current secrets
detect-secrets scan > .secrets.baseline
# Use in git hook to block new secrets
git diff --staged --name-only -z | xargs -0 detect-secrets-hook --baseline .secrets.baseline
Verify before relying
- Accuracy of the heuristic regex patterns and entropy checks against real-world secret types
- Performance impact when scanning large repositories or high-frequency pre-commit usage
- Customization depth available for organization-specific secret patterns beyond built-in plugins
Package facts
| License | Apache License 2.0 permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagespyyamlrequestsunidiff |
| Maintenance | Actively maintained 1 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,525,004 / month, #2,080 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software DevelopmentTopic :: UtilitiesTyping :: Typed |
Evidence: bc_detect_secrets-1.5.49-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secret detection in code”
- bc-detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…
- detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…
- trufflehog3Scans Git repositories and source code for secrets, API keys, and…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also cycode · detect-secrets · trufflehog3 · kingfisher-bin · truffleHog · dodgy · ggshield · pygitguardian · microsoft-security-utilities-secret-masker · flawfinder