diff --git a/detect_secrets/plugins/keyword.py b/detect_secrets/plugins/keyword.py index 868ade2b4..00a716716 100644 --- a/detect_secrets/plugins/keyword.py +++ b/detect_secrets/plugins/keyword.py @@ -40,15 +40,24 @@ # Note: All values here should be lowercase DENYLIST = ( - 'apikey', - 'api_key', - 'aws_secret_access_key', - 'db_pass', + 'api_?key', + 'auth_?key', + 'service_?key', + 'account_?key', + 'db_?key', + 'database_?key', + 'priv_?key', + 'private_?key', + 'client_?key', + 'db_?pass', + 'database_?pass', + 'key_?pass', 'password', 'passwd', - 'private_key', + 'pwd', 'secret', - 'secrete', + 'contraseƱa', + 'contrasena', ) # Includes ], ', " as closing CLOSING = r'[]\'"]{0,2}'