SAP/credential-digger

A Github scanning tool that identifies hardcoded credentials while filtering the false positive data through machine learning models :lock:

55
/ 100
Established

This tool helps security and development teams prevent accidental data exposure by scanning code repositories for hardcoded sensitive information like passwords, API keys, and tokens. It takes your GitHub or GitLab repository as input and identifies potential secrets, filtering out common false positives using machine learning to provide a more accurate list of findings. Security engineers and developers who want to ensure their code doesn't contain easily discoverable credentials would use this.

361 stars.

Use this if you need to automatically scan your code repositories to detect and manage hardcoded credentials, reducing the manual effort of reviewing numerous false positives.

Not ideal if you primarily work on Windows, require scanning for secrets in non-code assets, or need a solution that runs entirely offline without any external dependencies.

Application Security Code Review Secret Management DevSecOps Supply Chain Security
No Package No Dependents
Maintenance 10 / 25
Adoption 10 / 25
Maturity 16 / 25
Community 19 / 25

How are scores calculated?

Stars

361

Forks

54

Language

Python

License

Apache-2.0

Last pushed

Feb 03, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/ml-frameworks/SAP/credential-digger"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.