Ross ROSS = Recommend OSS · open-source software intelligence for agents

mazen160/secrets-patterns-db resource

Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more. observed · 2026-08-28

github.com/mazen160/secrets-patterns-db · homepage · Python · CC-BY-SA-4.0 (other) observed · 2026-08-28

Health v2 · maintenance only

47/100

  • Activity 35
  • Release rhythm 35
  • Longevity 93

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1303
  • days_rel: n/a
  • days_push: 392
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1609 stars · 190 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Secrets Patterns DB is the largest open-source database of over 1600 tested regular expressions for detecting secrets, API keys, passwords, and tokens. It provides conversion scripts to feed secret scanning engines like TruffleHog and Gitleaks with curated, ReDoS-validated patterns categorized by confidence level.

Use cases

  • find leaked api keys in git repositories
  • feed custom regex rules into gitleaks
  • convert secret patterns for trufflehog v3
  • improve secret detection coverage in an appsec program
  • detect hardcoded passwords and tokens in source code
  • source regex rules for a custom secret scanning engine

When to choose

  • you need broader secret detection coverage than built-in TruffleHog or Gitleaks rules provide
  • you want curated, ReDoS-tested regex patterns categorized by confidence
  • you maintain a secret scanning pipeline and want a community-maintained rule database

When to avoid

  • you need entropy-based secret detection rather than regex pattern matching
  • you need a full secret scanning tool rather than a pattern dataset
  • you require severity-level classification, which is not yet supported

Facets

dataset · maturity active

security vulnerability-scanning parser security developer-tools privacy cross-platform python cli secrets-detection regex-patterns gitleaks trufflehog api-keys secret-scanning appsec

3 sources

Member repositories

RepositoryRoleHealth v2
mazen160/secrets-patterns-dbmain47

For agents

markdown · JSON · MCP: product_card(name="mazen160/secrets-patterns-db")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem