7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source GitGuardian alternatives

A curated, ranked list of the 4 best open-source alternatives to GitGuardian.

The best open-source alternative to GitGuardian is Trivy. If that doesn't suit you, other good options are Gitleaks, Infisical and TruffleHog.

GitGuardian alternatives are mainly security tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 2 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Trivy

A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes.

GitHub stars
38k
Last commit
yesterday
Latest release
v0.75.0
Licence
Apache-2.0
trivy.devTrivy homepage screenshot

Trivy is a security scanner from Aquasec, written in Go and released under the Apache-2.0 license. It has scanners that look for different security issues and targets where those issues can be found. The README describes it as comprehensive and versatile, and it covers the major programming languages, operating systems and platforms.

Targets include container images, filesystems, remote Git repositories, virtual machine images and Kubernetes. Scanners look for OS packages and software dependencies in use, which produces an SBOM, known vulnerabilities (CVEs), infrastructure-as-code issues and misconfigurations, sensitive information and secrets, and software licenses. Its topics reference DevSecOps and vulnerability scanning.

Trivy is available through most common channels, including Homebrew, a Docker image and downloadable binaries, and integrates with platforms such as GitHub Actions, a Kubernetes operator and a VS Code plugin. Canary builds are produced with each push to the main branch. It suits developers, platform teams and security engineers who want to scan images and code in CI pipelines.

Key features

  • Scans container images and filesystems
  • Scans Git repositories and Kubernetes
  • Known vulnerability (CVE) detection
  • IaC misconfiguration and secret detection
  • SBOM generation and license scanning
  • GitHub Actions and VS Code integrations

Pricing: Free and open source under the Apache-2.0 license.

Read more about TrivyWebsite GitHub

Gitleaks

Gitleaks is a command-line scanner that finds hardcoded passwords, API keys and tokens in git repositories, files and piped input.

GitHub stars
30k
Last commit
3 days ago
Latest release
v8.30.1
Licence
MIT
gitleaks.ioGitleaks homepage screenshot

Gitleaks is a tool for detecting secrets such as passwords, API keys and tokens in git repositories, in files, and in anything you pipe to it through standard input. It is written in Go, released under the MIT license, and aimed at DevSecOps, CI/CD and data-loss-prevention use. A maintainer warning in the README says it is feature complete, that future releases will be security patches only, and that the author is shifting focus to a successor project called Betterleaks.

Gitleaks can be installed with Homebrew, Docker or Go, and binaries for many platforms are on the releases page. It can run as a pre-commit hook and has a GitHub Action for CI use. The detection engine is built on regular expressions, and the author has written about how that approach works. It does not need a hosted service, because scans run wherever you execute the binary, including in CI pipelines.

Key features

  • Scans git history, files and stdin
  • Detects passwords, API keys and tokens
  • Runs as a pre-commit hook
  • GitHub Action for CI scanning
  • Install via Homebrew, Docker or Go
  • Maintenance now limited to security patches

Pricing: Free and open source under the MIT license.

Read more about GitleaksWebsite GitHub

Infisical

Infisical is an open-source platform for managing secrets, certificates and privileged access, with syncing, rotation and leak prevention.

GitHub stars
30k
Last commit
today
Latest release
v0.165.16
Self-hosted
Yes
Hosted version
Available
infisical.comInfisical homepage screenshot

Infisical is an open-source security infrastructure platform used by teams to manage application secrets, certificates and privileged access. It centralizes secrets and configuration across environments, with versioning, rotation and leak prevention. The stack is TypeScript and Go on PostgreSQL, and the project offers both a hosted Infisical Cloud and a self-hosting option.

Secrets are organized by project and environment, such as development and production, in a dashboard. Secret syncs push values to platforms like GitHub, Vercel and AWS and work with tools such as Terraform and Ansible. Further features include point-in-time recovery, scheduled rotation for databases and AWS IAM, ephemeral dynamic secrets, secret scanning that stops leaks into git, a Kubernetes operator, and an agent that injects secrets without code changes. It also offers honey tokens as decoy credentials and brokered access for AI agents. The repository metadata lists the license as Other, so check it for exact terms.

Key features

  • Secrets dashboard across projects and environments
  • Secret syncs to GitHub, Vercel and AWS
  • Versioning with point-in-time recovery
  • Automatic secret rotation and dynamic secrets
  • Secret scanning to prevent leaks into git
  • Kubernetes operator and injection agent

Pricing: Free for up to 5 identities. Pro is $23 and Advanced $46 per identity per month, or $20 and $40 billed annually; Enterprise is custom. Paid plans include a free trial.

TruffleHog

TruffleHog finds, classifies and verifies leaked credentials across Git, chats, wikis, logs, filesystems and cloud storage.

GitHub stars
28k
Last commit
yesterday
Latest release
v3.97.9
Licence
AGPL-3.0
Self-hosted
Yes
trufflesecurity.comTruffleHog homepage screenshot

TruffleHog is a tool for discovering, classifying, validating and analyzing secrets, meaning credentials a machine uses to authenticate to another machine, such as API keys, database passwords and private keys. It is written in Go and released under the AGPL-3.0 license. It can be used from the command line and in pre-commit and CI scans as part of DevSecOps work.

Discovery reaches into Git repositories, chat tools, wikis, log files, API testing platforms, object stores and filesystems. Classification identifies more than 800 secret types and maps each to the identity it belongs to. Validation attempts to log in with the found secret to confirm whether it is still live, and analysis for roughly twenty common credential types sends further requests to learn who created the secret and what it can access. Truffle Security also sells an enterprise product that monitors systems such as Git, Jira, Slack and Confluence.

Key features

  • Scans Git, chats, wikis, logs and filesystems
  • Classifies over 800 secret types
  • Validates whether a found secret is live
  • Analyzes permissions of common credential types
  • Runs from the CLI and in pre-commit checks
  • Enterprise monitoring product available separately

Pricing: The open-source edition is free. Enterprise adds a dashboard, integrations, SSO and priority support, with pricing available by contacting the vendor.

GitGuardian alternatives: questions

What is the best open-source alternative to GitGuardian?
Trivy is the top-ranked open-source alternative to GitGuardian on Enlisted: A security scanner that finds vulnerabilities, misconfigurations, secrets and license issues in container images, filesystems, Git repositories and Kubernetes. Other strong options are Gitleaks, Infisical and TruffleHog.
Are these GitGuardian alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of GitGuardian alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all