Betterleaks is a Open Source Windows program in the Developer Tools category, developed by Zachary Rice. The current version is 1.5.0; you can download it safely from its official source with the download button above.
Betterleaks is a tool for finding secrets like passwords and API keys.
✨ Features
cicdcredentialsdeveloper-toolsdevopsdevsecopsgitgithubgitleaksgogolangllm-toolsnhisecretsecrets
📝 Release notes (1.5.0)
What's New
- Added 50 new rules w/ validation
1. aikido-ci-token
2. aikido-client-id
3. aikido-client-secret
4. airtable-oauth-token
5. alibaba-sts-access-key-id
6. alibaba-sts-access-key-secret
7. alibaba-sts-security-token
8. amplitude-secret-key
9. artifactory-jfrog-url
10. bitly-access-token
11. box-api-access-token
12. brave-search-api-key
13. canva-client-id
14. canva-client-secret
15. clerk-secret-key
16. clickhouse-cloud-key-id
17. clickup-personal-api-token
18. cloudinary-api-key
19. cloudinary-api-secret
20. cloudinary-cloud-name
21. cockroachlabs-cloud-api-key
22. configcat-sdk-key
23. configcat-sdk-key-extended
24. couchbase-capella-api-key
25. coveralls-personal-api-token
26. datadog-api-key
27. datadog-application-key
28. datagov-api-key
29. deno-account-token
30. devin-personal-api-key
31. devin-service-api-key
32. devin-service-user-token
33. disqus-api-key
34. dockerhub-organization-access-token
35. dockerhub-personal-access-token
36. etsy-open-api-key
37. gumroad-access-token
38. honeycomb-api-key
39. ibm-cloud-user-api-key
40. influxdb-api-token
41. jumpcloud-api-key
42. kagi-api-key
43. kimi-api-key
44. klaviyo-api-key
45. minimax-api-key
46. supabase-management-token
47. supabase-project-api-key
48. supabase-project-url
49. zai-api-key
- Archive handling is enabled by default (turn off with --max-archive-depth=0)
- Added a env.getOrDefault cel binding
- migrated from spf13/viper to go-toml for config parsing and loading
- various bug fixes
Changelog
- 2b62eee Fix redaction of capture groups and multi-byte values (#176)
- 21585e7 Make ValidationStatus a typed enum (#174)
- 93cda77 Refactor/config parse (#191)
- 5324a7d Rules/more rules 3 (#196)
- 5b64a83 Rules/more rules 4 (#197)
- cbb6597 Surface the real git stderr instead of a generic error (#190)
- ea5f4cd add getOrDefault binding (#205)
- e2ae8d5 bunch more, use validate.unknown (#198)
- 7d3d8bf count rule script
- 6ec7f6e detect: make config/baseline self-scan guard separator-insensitive (#178)
- d3fbd5d dir: surface scan errors so a failed scan exits non-zero (#177)
- 43f1e4f drop translate filter logging to trace (#192)
- ac65f47 enable archive handling by default (#206)
- 3027ec5 feat(github): validate tokens against GHES base URL (#159)
- 9f55833 first batch of new rules (#194)
- 1fa3aed fix(curl-auth-user): filter nested bash parameter expansions as false positives (#186)
- 582b8c6 how did I not have supabase (#193)
- 86f6b05 mock files when piping (#203)
- d627481 more rules, removed redundant jfrog (#195)
- 0dba832 report a clean error for an unknown --regex-engine instead of panicking (#181)
- 8daf457 small regex tweaks (#202)
- 24d272c zai minimax kimi (#204)
SHA-256: 210852DC72B037422FAFB1D053209B352D271300473C7DAFCA2560CEF68EBA15