About Gitleaks
Gitleaks is a tool for detecting secrets such as passwords, API keys and tokens in git repositories, in files, and in anything you pipe to it through standard input. It is written in Go, released under the MIT license, and aimed at DevSecOps, CI/CD and data-loss-prevention use. A maintainer warning in the README says it is feature complete, that future releases will be security patches only, and that the author is shifting focus to a successor project called Betterleaks.
Gitleaks can be installed with Homebrew, Docker or Go, and binaries for many platforms are on the releases page. It can run as a pre-commit hook and has a GitHub Action for CI use. The detection engine is built on regular expressions, and the author has written about how that approach works. It does not need a hosted service, because scans run wherever you execute the binary, including in CI pipelines.
Key features
- Scans git history, files and stdin
- Detects passwords, API keys and tokens
- Runs as a pre-commit hook
- GitHub Action for CI scanning
- Install via Homebrew, Docker or Go
- Maintenance now limited to security patches
Good fit for
- →Blocking committed secrets in CI
- →Auditing old repositories for leaked keys
- Built with
- Go
- Tags
- secret-scanning
- security
- git
- devsecops
- ci-cd
- golang
- dlp
- pre-commit
Gitleaks: questions and answers
- What is Gitleaks used for?
- Gitleaks is a command-line scanner that finds hardcoded passwords, API keys and tokens in git repositories, files and piped input. It is a good fit for blocking committed secrets in CI and auditing old repositories for leaked keys.
- Is Gitleaks open source?
- Yes. Gitleaks is open source under the MIT licence. Its source code is on GitHub at gitleaks/gitleaks and is written mainly in Go.
- Is Gitleaks free?
- Yes. Gitleaks is open source, so the software itself is free to use.
- What is Gitleaks an alternative to?
- Gitleaks is an open-source alternative to GitGuardian and Aikido Security. Other open-source alternatives to GitGuardian include TruffleHog and Trivy.
- Is Gitleaks actively maintained?
- Yes. The most recent commit to Gitleaks was on 30 September 2026, and the latest release is v8.30.1, published on 21 March 2026. The project has 30k stars on GitHub.
Open-source alternatives to Gitleaks
See all
TruffleHog
Security
Find, verify, and analyze leaked credentials
AGPL-3.0vs GitGuardian★ 28k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
SaaS alternatives to Gitleaks
See all
GitGuardian
Security
Detects leaked secrets and credentials in code repositories and developer tools
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
AuditYourApp
Security
Scans Supabase projects, websites and mobile apps for exposed RLS rules, open RPCs and leaked API keys
SaaSBeesecure
Security
Security scanning platform that finds vulnerabilities in codebases for developers and indie hackers
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS

