A single Go binary that gates your repo before it ever ships — scanning for leaked credentials and known-vulnerable dependencies in one command. No accounts. No network calls. No excuses.
$ cipherwall scan ./my-repo
[CRITICAL] config/settings.yaml:1 possible credential leak
AKIA....MPLE
[CRITICAL] .env:1 possible credential leak
ghp_....23456
2 finding(s): 2 critical| Layer | What it catches |
|---|---|
| 🩸 Secrets | AWS keys · GitHub/GitLab tokens · Slack webhooks · Stripe keys · private keys · high-entropy strings |
| 🧬 Dependencies | go.mod · package.json · requirements.txt · Cargo.toml against a bundled offline advisory DB |
- Fully offline — bundled advisory DB, zero network calls
- Detected secrets are masked in every output format (
AKIA....MPLE) — never leaked twice - One static binary — no runtime, no deps, works in CI, hooks, and air-gapped environments
git clone https://github.com/urlvnashezna/cipherwall.git && cd cipherwall
go build -o bin/cipherwall ./cmd/cipherwall
cipherwall init # write cipherwall.yaml
cipherwall scan . # scan this very repo🧪 Output formats
cipherwall scan . --format json # jq-ready
cipherwall scan . --format sarif # GitHub code scanning
cipherwall scan . --format csv # spreadsheets / auditsscan:
exclude: ["vendor/", "node_modules/", "*.lock"]
secrets:
entropy_threshold: 4.2 # Shannon entropy cutoff
min_length: 16 # ignore short strings
dependencies:
min_severity: high # noise floor
output:
format: table # table | json | sarif | csv
exit_nonzero_on_findings: true # CI-friendly.
├── cmd/cipherwall/ entrypoint
├── internal/
│ ├── cli/ cobra command surface
│ ├── config/ cipherwall.yaml load/validate
│ ├── scanner/ regex + entropy secret detection
│ ├── deps/ manifest scanning + advisory DB
│ ├── finding/ findings model + severity
│ └── output/ table · json · sarif · csv
├── config.example.yaml
├── go.mod
├── Makefile
└── docs/ usage · secrets
- Usage & CI — including the pre-commit hook recipe
- Secret detection reference — every rule + tuning knobs
MIT — do what you want, just don't blame us.
Scan before you ship.