Open source project / 2026
TokenGuard
A zero-dependency pre-commit scanner for detecting API keys and credentials in staged Git changes.
Context
Accidentally committed secrets are one of the most widespread security incidents, and cleanup after a push is costly and noisy.
The problem
Developers need a fast local gate that catches tokens, private keys and high-entropy strings before commit — without sending code anywhere.
Approach
TokenGuard scans staged changes with pattern rules plus Shannon entropy analysis, and lets teams suppress accepted test credentials through an explicit baseline file.
System architecture
Pure Python standard library, zero external dependencies; results are emitted as OASIS SARIF v2.1.0 for GitHub Code Scanning integration.
Key decisions
Every finding carries a severity, masked value preview, entropy score and a concrete remediation action — no vague warnings.
Outcome
Available on PyPI as tokenguard-cli. It scans staged changes, masks detected values in reports and supports pre-commit hooks and SARIF output. Pattern and entropy checks do not guarantee detection of every secret.
Learnings
Security tooling gets adopted when it is fast, offline and explains exactly what to do next.