Skip to content

build(deps): bump github.com/betterleaks/betterleaks/v2 from 2.0.0-20260929212625-fa62e6aaad9d to 2.0.0-rc.1 - #739

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/github.com/betterleaks/betterleaks/v2-2.0.0-rc.1
Oct 7, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/go_modules/github.com/betterleaks/betterleaks/v2-2.0.0-rc.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/betterleaks/betterleaks/v2 from 2.0.0-20260929212625-fa62e6aaad9d to 2.0.0-rc.1.

Release notes

Sourced from github.com/betterleaks/betterleaks/v2's releases.

v2.0.0-rc.1

Betterleaks v2.0.0-rc.1 is the first release candidate for v2, bringing a reworked scanning engine, credential identity and permissions analysis, explicit revocation, and a simpler CLI and Go SDK.

This is a prerelease. Breaking changes to the CLI, configuration, report formats, and Go API may still land before v2.0.0. We'd appreciate feedback on detection results, performance, integrations, and the upgrade from v1.

What's new

Credential analysis goes beyond checking whether a secret works. Supported rules can extract the identity behind a credential, report its capabilities, and derive a severity from the permissions discovered. This release candidate includes analysis expressions for 42 rules, covering credentials from providers such as AWS, GitHub, GitLab, Cloudflare, Slack, and Hugging Face. Identity and permission details depend on what each provider exposes; severity remains unknown when there is no positive capability evidence. Analysis happens asynchronously during scans, so its results are available when findings are reported. No extra follow-up commands are needed. See the credential analysis reference for the identity, capability, and severity model.

Scans detect secrets without credential validation or analysis by default. Use -v / --validate to check credentials, or -a / --analyze to validate and analyze them. Analysis implies validation, so -a alone enables both stages. BETTERLEAKS_VALIDATE and BETTERLEAKS_ANALYZE enable the same behavior through the environment, with explicit flags taking precedence. Fetching remote scan sources can still use the network in any mode.

The standalone validate and new analyze commands also work with credentials you already have, including multipart credentials. The new revoke command provides explicit revocation for supported rules, with revocation expressions included for 13 rules in this candidate. Revocation is always a separate action; scans never revoke credentials.

Scanning and reporting have been reworked for throughput and memory use. File reads and detection overlap through bounded queues, regex matching avoids unnecessary work, and JSON and JSONL reports stream findings without retaining the entire result set. -j / --jobs controls detection concurrency independently of provider requests. BPE filtering uses a new dedicated tokenizer while keeping its vocabulary embedded in the binary. Local benchmarks showed substantial throughput gains; improvements in total scan time depend on the workload and how much additional content v2 inspects.

Three-run medians on an Apple M5 (16 GiB RAM). Paired values show v1 → v2; speedup compares throughput.

Dataset Files Throughput (MB/s) Speedup Peak RSS (MB) Time (s)
40 GB repo collection 1.93M 284 → 498 1.75× 335 → 259 132.91 → 84.49
7.2 GB repo collection 302K 106 → 687 6.49× 195 → 141 67.20 → 16.60
3.8 GB GitLab 93K 62 → 785 12.58× 158 → 126 60.35 → 7.53
1.55 GB Linux 92K 376 → 595 1.58× 184 → 105 4.11 → 2.60
347 MB Rails 4.9K 55 → 443 8.01× 124 → 98 6.14 → 0.77

Coverage is broader: files are no longer skipped solely because they look binary, and the default filters allow .git contents and more document, executable, and archive formats through. Git history scans can additionally inspect commit messages, tag messages, and reflogs with --include. Broader coverage can mean more findings and more bytes inspected than v1; scanning .git files is distinct from scanning reconstructed Git history.

Everyday commands take less setup. Pass a local path or supported URL directly to Betterleaks to select the source automatically, or use url to scan a single HTTP response or downloaded archive. Git scans accept HTTP(S) repository URLs, and git --staged and git --unstaged scan added lines in local changes. Findings print by default; -s / --silent suppresses findings and the banner, while -o results.json or -o results.jsonl selects a report format by extension. The scanning guide covers source selection, concurrency, output, and credential commands with examples.

Reports carry more context for people and integrations. Versioned JSON and JSONL envelopes include scan summaries with configuration identity, timing, bytes inspected, finding totals, and completion state. Findings include rule hashes, value fingerprints, structured locations, and explicit decoding metadata. Terminal output makes binary and decoded matches easier to inspect.

For integrations, the scan report schema defines the JSON document and JSONL record envelopes. JSON contains schema_version, findings, and scan; JSONL emits individual finding records followed by a final scan record, even when no secrets are found. Both currently use schema_version: "1". The finding schema describes each finding and its analysis, while the credential report schema covers standalone validation, analysis, and revocation results. See the output guide for reporting and decoding details.

Ignoring a known value no longer depends on where it appeared. .betterleaksignore uses value fingerprints that stay consistent across files, commits, and sources; betterleaks fingerprint generates entries from stdin. Optional HMAC fingerprints, configured through --hmac-key or BETTERLEAKS_FINGERPRINT_HMAC_KEY, let you use a private key for those identifiers.

Custom rules and SDK integrations have clearer boundaries. Source prefilters and finding filters have separate roles, and multipart rules can attach required or optional components with line or character proximity constraints. config check checks regexes and expressions without contacting providers, while config hash identifies resolved configurations or individual rules. Unknown TOML fields and duplicate rule IDs now produce errors. The configuration reference documents rule definitions, Expr filters, components, and provider operations.

The Go SDK separates detection (scan.Scanner), credential evaluation (analyze.Analyzer), and their composition (pipeline). Scanners and analyzers can be reused concurrently, constructors take explicit options, and logging is opt-in through slog. The SDK defaults to Go's standard regex engine, with RE2 available as an explicit choice. Runnable examples cover detection only, validation and analysis, custom configurations, and concurrent scans.

Upgrading and trying the release candidate

Read the v2 migration guide before updating scripts or integrations. In particular, -v now enables validation instead of verbose output; findings already print by default. Replace --validation with --validate. Earlier v2 development flags --offline and --no-analysis are removed.

Custom configurations must be selected explicitly with --config, BETTERLEAKS_CONFIG, or BETTERLEAKS_CONFIG_TOML; target-local configuration discovery and GITLEAKS_* aliases are removed. Custom rules need the v2 configuration format, and overriding an inherited rule replaces its whole definition. JSON consumers must handle the new envelope and finding schema, and JSONL consumers must handle the final scan summary. CSV, SARIF, JUnit, and template output are removed, as is baseline-report suppression. Existing location-based ignore entries must be replaced with value fingerprints. SDK users must update imports to github.com/betterleaks/betterleaks/v2 and use Go 1.25 or newer.

Download an archive from this release, or install the exact candidate with Go:

go install github.com/betterleaks/betterleaks/v2@v2.0.0-rc.1

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/betterleaks/betterleaks/v2](https://github.com/betterleaks/betterleaks) from 2.0.0-20260929212625-fa62e6aaad9d to 2.0.0-rc.1.
- [Release notes](https://github.com/betterleaks/betterleaks/releases)
- [Commits](https://github.com/betterleaks/betterleaks/commits/v2.0.0-rc.1)

---
updated-dependencies:
- dependency-name: github.com/betterleaks/betterleaks/v2
  dependency-version: 2.0.0-rc.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Oct 7, 2026
@github-actions
github-actions Bot enabled auto-merge October 7, 2026 21:43
@github-actions
github-actions Bot merged commit 8784821 into main Oct 7, 2026
14 checks passed
@github-actions
github-actions Bot deleted the dependabot/go_modules/github.com/betterleaks/betterleaks/v2-2.0.0-rc.1 branch October 7, 2026 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants