secrets scan takes a git repository and walks every blob in its history. The detector itself operates on individual blobs, so it could also cover inputs that are not git repositories: an extracted tarball, a build workspace, a vendored directory.
Proposal: a mode that walks a directory tree and runs each file through the same detection path, skipping the commit attribution layer, e.g. secrets scan --dir PATH. Path filters and --max-blob-size apply as they do today. Alongside the CLI, an exported entry point accepting an fs.FS would let other Go programs run the detector against non-git inputs.
secrets scantakes a git repository and walks every blob in its history. The detector itself operates on individual blobs, so it could also cover inputs that are not git repositories: an extracted tarball, a build workspace, a vendored directory.Proposal: a mode that walks a directory tree and runs each file through the same detection path, skipping the commit attribution layer, e.g.
secrets scan --dir PATH. Path filters and--max-blob-sizeapply as they do today. Alongside the CLI, an exported entry point accepting anfs.FSwould let other Go programs run the detector against non-git inputs.