惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
腾讯CDC
Jina AI
Jina AI
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
GbyAI
GbyAI
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
T
The Blog of Author Tim Ferriss
小众软件
小众软件
M
MIT News - Artificial intelligence
MyScale Blog
MyScale Blog
D
Docker
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
月光博客
月光博客
L
LangChain Blog
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky
C
Check Point Blog
U
Unit 42
人人都是产品经理
人人都是产品经理

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
keygate: A Fast Pre-Commit Guardrail Against Secret Leaks
YUICHI KANEK · 2026-04-24 · via DEV Community

YUICHI KANEKO

Accidentally committing an API key, password, or private key is still one of the easiest ways to create a serious security incident. The problem gets worse as development speeds up: larger diffs, faster iterations, and more code being drafted by AI coding agents before a human reviews every line.

That is why I built keygate: a lightweight Git pre-commit hook that scans only staged added lines and blocks likely secrets before they enter repository history.

keygate is intentionally narrow in scope. It is not trying to replace full-repository scanners or cloud security platforms. Instead, it focuses on the moment that matters most in local development: right before git commit succeeds.

GitHub: https://github.com/kanekyuichi/keygate
PyPI: https://pypi.org/project/keygate/

Why I built it

Most secret leaks are not dramatic breaches. They start as small mistakes:

  • a real API key copied into a config file during debugging
  • a password left in a test fixture
  • a .env value pasted into code "just for now"
  • a generated diff that includes credentials no one noticed in review

Once committed, the value is part of Git history. Even if you delete it later, the exposure may already have happened.

Existing tools are useful, but I wanted something optimized for the local developer workflow:

  • fast enough for a Git hook
  • offline by default
  • focused on staged changes, not a full repo sweep
  • practical about false positives
  • usable both by humans and by AI agents

What keygate does

keygate combines multiple signals instead of relying on a single regex:

  • rule-based detection for known formats such as AWS keys, OpenAI keys, GitHub tokens, Slack tokens, PEM private keys, JWTs, Stripe keys, SendGrid keys, and URLs with embedded credentials
  • entropy checks for long random-looking strings
  • context scoring for signals like api_key, password, assignment syntax, and sensitive paths such as .env or config files

The final result is scored as:

  • block at 70+
  • warn at 40-69
  • ignored below 40

This keeps the hook fast while avoiding the worst tradeoff in secret scanning: either missing real secrets or becoming so noisy that developers disable it.

Built for modern local workflows

I also designed keygate for the reality that AI agents now write a meaningful share of code changes.

When tools like Codex or Claude Code generate larger diffs, the safest assumption is not that the agent is malicious, but that speed increases the chance of unnoticed sensitive values reaching a commit. A local guardrail becomes more valuable in that workflow, not less.

That is why keygate includes structured JSON output in addition to human-readable CLI output:

keygate scan --format json
keygate scan --json
keygate scan --profile agent

Enter fullscreen mode Exit fullscreen mode

That makes it easier for scripts or coding agents to re-run the scan, parse findings, and suggest fixes mechanically.

Handling false positives without breaking flow

A secret scanner is only useful if developers can live with it every day. keygate includes three escape hatches for expected findings:

  1. Inline ignore comments with a required reason
  2. Allowlist rules in keygate.toml
  3. A baseline file for existing findings you want to suppress safely

The baseline stores fingerprints rather than raw secret values, so teams can commit the file without exposing the secret itself.

Quick start

pipx install keygate
cd your-project
keygate install-hook

Enter fullscreen mode Exit fullscreen mode

From that point on, every normal git commit gets a fast local secret check automatically.

Project goals

The design goals are simple:

  • stop likely secrets before commit
  • keep the check fast enough for daily use
  • work offline
  • avoid LLM or external API dependence
  • give clear remediation when something is blocked

If you want a local, developer-friendly secret scanner that acts as a commit-time guardrail, that is exactly the gap keygate is meant to fill.

Links