Expand description
Local secret detection with an independent Rust engine and redacted output.
Scanning never validates credentials against a provider. A successful call
can contain findings; scan errors are separate from findings. Inspect
ScanReport::complete before treating an empty result as a clean scan.
Re-exports§
pub use context::ScanContext;pub use engine::Engine;pub use engine::EngineConfig;pub use engine::Finding;
Modules§
- archive
- Bounded, in-memory archive scanning. Members are never extracted to disk.
- baseline
- Stable secret identities with optional human review dispositions.
- context
- The selected input scope and detection policy used by a scan.
- engine
- Independent compile-once keyword and regex secret detection.
- mcp
- Read-only MCP 2025-11-25 over newline-delimited stdio JSON-RPC.
- report
- Machine-readable output. Findings contain redacted values only.
- rules
- Rule schema and compilation for the independent detection engine.
- scan
- Filesystem and local Git acquisition. No remote connections are made.