Skip to content

About

Secret and dependency scanner - regex + entropy detection, offline advisory DB

Resources

Stars

25 stars

Watchers

1 watching

Forks

Latest commit

 

History

648 Commits

Folders and files

Repository files navigation

The repo security gate you run before you push.

Go License: MIT Offline-first SARIF


🔐 What Cipherwall is

A single Go binary that gates your repo before it ever ships — scanning for leaked credentials and known-vulnerable dependencies in one command. No accounts. No network calls. No excuses.

$ cipherwall scan ./my-repo

[CRITICAL] config/settings.yaml:1  possible credential leak
      AKIA....MPLE
[CRITICAL] .env:1  possible credential leak
      ghp_....23456

2 finding(s): 2 critical

🗡️ The two-layer defense

Layer What it catches
🩸 Secrets AWS keys · GitHub/GitLab tokens · Slack webhooks · Stripe keys · private keys · high-entropy strings
🧬 Dependencies go.mod · package.json · requirements.txt · Cargo.toml against a bundled offline advisory DB

⚡ Fast. Local. Private.

  • Fully offline — bundled advisory DB, zero network calls
  • Detected secrets are masked in every output format (AKIA....MPLE) — never leaked twice
  • One static binary — no runtime, no deps, works in CI, hooks, and air-gapped environments

🚀 Quick start

git clone https://github.com/urlvnashezna/cipherwall.git && cd cipherwall
go build -o bin/cipherwall ./cmd/cipherwall
cipherwall init                     # write cipherwall.yaml
cipherwall scan .                   # scan this very repo
🧪 Output formats
cipherwall scan . --format json     # jq-ready
cipherwall scan . --format sarif    # GitHub code scanning
cipherwall scan . --format csv      # spreadsheets / audits

⚙️ Configuration

scan:
  exclude: ["vendor/", "node_modules/", "*.lock"]
secrets:
  entropy_threshold: 4.2            # Shannon entropy cutoff
  min_length: 16                    # ignore short strings
dependencies:
  min_severity: high                # noise floor
output:
  format: table                     # table | json | sarif | csv
  exit_nonzero_on_findings: true    # CI-friendly

📁 Layout

.
├── cmd/cipherwall/       entrypoint
├── internal/
│   ├── cli/              cobra command surface
│   ├── config/           cipherwall.yaml load/validate
│   ├── scanner/          regex + entropy secret detection
│   ├── deps/             manifest scanning + advisory DB
│   ├── finding/          findings model + severity
│   └── output/           table · json · sarif · csv
├── config.example.yaml
├── go.mod
├── Makefile
└── docs/                 usage · secrets

📚 Docs

🛡️ License

MIT — do what you want, just don't blame us.


Scan before you ship.

About

Secret and dependency scanner - regex + entropy detection, offline advisory DB

Resources

Stars

25 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages