CodeRiskTools Secret Scanner Engine 3.0.0
CodeRiskTools Secret Scanner Engine 3.0.0
First public release of the MIT-licensed Scanner flagship.
Included
- local-first secret-like value scanning across bounded file and diff inputs;
- strict bounded unified-diff parsing;
- staged-change and bounded Git-history scanning;
- pre-commit hook and composite GitHub Action;
- JSON, Markdown, HTML, SARIF and GitHub output;
- redacted findings, reviewed fingerprint baselines and allowlists;
- Python 3.10–3.13 CI coverage.
Security and provenance
- GitHub Push Protection passed without bypasses;
- Private Vulnerability Reporting enabled;
- 332 tests ran: 331 passed, 1 skipped;
- self-scan: 0 new / 58 matched / 0 stale;
- independent audit: PASS B0/H0/M0/L0;
- attached wheel is reproducible and covered by
SHA256SUMS.txtandBUILD_PROVENANCE.txt.
Product boundary
This repository and release contain only Secret Scanner Engine source. MCPwatch Scanner is a paid proprietary add-on. AI Change Firewall is a separate paid proprietary product. Neither proprietary codebase is included.
Important limitation
A clean scan is not proof that code is secure. Findings can include false positives and false negatives. This release is not a security audit, certification, compliance guarantee or legal opinion.