Skip to content

Add dotenv-exposure-check to Secret Detection#3

Open
Perufitlife wants to merge 1 commit into
Escape-Technologies:mainfrom
Perufitlife:add-dotenv-exposure-check
Open

Add dotenv-exposure-check to Secret Detection#3
Perufitlife wants to merge 1 commit into
Escape-Technologies:mainfrom
Perufitlife:add-dotenv-exposure-check

Conversation

@Perufitlife

Copy link
Copy Markdown

Adds dotenv-exposure-check to the (currently empty) Secret Detection section.

It's an open-source (MIT, zero-dependency) CLI that probes a live URL for accidentally-served secret artifacts — .env, .git/, JS .map source maps, .DS_Store, backups — and confirms each hit by fetching the bytes. Fits a DevSecOps pipeline as a post-deploy check for leaked secrets on a running endpoint.

Disclosure: I'm the author of this tool.

Repo: https://github.com/Perufitlife/dotenv-exposure-check

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant