Repository navigation
Releases: hbenali/logscrub
Release list
1.1.1
A small release: the web UI has a sample log to try, logscrub serve prints a URL you can actually open, and there is now an online demo that runs entirely in your browser.
Online demo: https://logscrub.hbenali.ovh/ is the real UI with the engine compiled to WebAssembly and hosted as a static page. There is no server, so what you paste never leaves your browser; its CSP only allows its own files, and a test in a real browser asserts that no request leaves the page or carries the text. (The tool itself is unchanged by this: the demo is a separate build of the same engine.)
Fixes and small additions:
logscrub serve --allow-remote --addr 0.0.0.0:PORTprintedhttp://[::]:PORT/#token=..., which a browser cannot open; it now printslocalhost.- The web UI has a "Load sample" button (a made-up log with documentation-range addresses and an example key).
- The scrub request handling moved into a shared package used by both the server and the browser build; behaviour and the server's security tests are unchanged.
No flag, exit code, output format or detector changed. All files are checksummed and individually attested (gh attestation verify FILE --repo hbenali/logscrub); the image is on Docker Hub (hbenali/logscrub) and GHCR with an identical digest.
Pattern matching cannot find secrets with no recognisable shape; review the output before sharing it.
1.1.0
More secrets and personal data caught, reports for CI, a safer web UI, and much easier to install and adopt. No 1.0 flag, exit code or output format changed.
Heads-up (new default-on detectors). Provider tokens, cookies, IBANs and user names in home-directory paths are on by default, so logs that were clean under 1.0 can now contain matches (for example /home/alice/... becomes /home/[REDACTED:home-path]/...; /home/runner and similar role accounts are left alone). --disable ID restores the old behaviour for any of them; --check shows what changed.
New detectors: Docker Hub, Anthropic, OpenAI, Google, npm, PyPI, SendGrid, Hugging Face, Shopify, DigitalOcean, Vault, age, Telegram and Azure storage keys; Cookie / Set-Cookie values; session_id and credentials fields; IBANs (checksum-verified); home-directory user names. Opt-in: us-ssn, mac-address, high-entropy. Throughput is unchanged (about 10 MB/s). Reference: the wiki's Detectors page.
CI and reporting: --report-format json|sarif (file, line, byte range; never the matched text; SARIF 2.1.0 works with code scanning); --output/-o writes atomically with mode 0600 and refuses to overwrite its input; a per-user config file ($XDG_CONFIG_HOME/logscrub/config.toml) is read unless world-writable, and a config in the current directory is deliberately never read (an allow-list in an untrusted checkout could make logscrub leak).
Web UI: --allow-remote now requires an access token (generated and printed in a URL fragment, or --token-file / LOGSCRUB_TOKEN), compared in constant time. The result tabs are keyboard operable and an axe-core audit finds zero violations in light, dark and mobile layouts.
Install and adopt: .deb, .rpm and .apk packages (amd64 and arm64) with the man page and shell completions; logscrub completion bash|zsh|fish; a man page; a GitHub Action (uses: hbenali/logscrub@1.1.0, verifies the release checksum) and a pre-commit hook; archives now include the licence, man page and completions.
Supply chain: every archive and package has its own build-provenance attestation: gh attestation verify FILE --repo hbenali/logscrub. The image is on Docker Hub (hbenali/logscrub) and GHCR with an identical digest.
Tested on Linux, macOS and Windows in CI, the packages in Debian, Fedora and Alpine containers, the arm64 image under QEMU, and the web UI in a real browser. Not tested: zsh and fish completions beyond a syntax check, and screen-reader use of the web UI.
Pattern matching cannot find secrets with no recognisable shape; review the output before sharing it.
1.0.0
logscrub 1.0.0: mask secrets and personal data in logs so they can be shared safely. Every feature in the specification (docs/SPEC.md) is implemented.
some-command | logscrub > clean.log
logscrub --check app.log # CI gate: exit 1 if anything would be masked
logscrub --mode pseudonym app.log # stable tags for emails and IPs
logscrub serve # local web UIWhat it masks: AWS keys, GitHub / GitLab / Slack / Stripe tokens, JWTs, PEM private keys (including multi-line blocks), Authorization headers, URL credentials, password= / token= / "api_key": ... pairs, email addresses, IPv4 and IPv6 addresses, payment card numbers (Luhn-checked) and, opt-in, phone numbers.
Modes and tools: fixed markers or stable HMAC pseudonyms; a strict TOML config (enable/disable, allow-list, custom RE2 rules); --check and --report for CI (counts only, never the matched text); a local web UI with highlighted matches.
Design: Go's RE2 engine (linear time, no ReDoS); streaming with bounded memory, and a line that cannot be scanned safely is an error, never passed through; no network access; errors and reports never contain input text. A "must not change" corpus of realistic logs, property and chunking tests, and fuzzing guard against false positives and leaks. The web UI binds to loopback only, checks Host and Origin, sends a strict CSP and loads nothing from other sites.
New since 0.3.0: --max-private-key-lines (CLI and serve) bounds how much of a private key block that never closes is masked; a warning is printed when the limit is hit.
Stability: from 1.0, the flags, exit codes, config format and the [REDACTED:id] / [kind:tag] output formats are stable across 1.x. New detectors may be added in minor releases, so a previously clean log can gain matches; --check is how to notice.
Install: archives below (linux, macOS, windows; amd64 and arm64; verify with checksums.txt), docker run --rm -i hbenali/logscrub < app.log (also ghcr.io/hbenali/logscrub), or go install github.com/hbenali/logscrub/cmd/logscrub@latest.
Known limitations: pattern matching cannot find secrets with no recognisable shape (a password in prose, an unlabelled random string) or encoded ones; a plain name: value line is only masked when it looks like YAML; a private key block longer than the limit is only masked up to it. Review the output before sharing it publicly.
0.3.0
Adds a local web UI, documentation screenshots and a banner, and publishes the image to Docker Hub as well as GHCR.
Web UI: logscrub serve opens a page at http://127.0.0.1:8080. Paste or drop a log, see every match highlighted by detector, toggle detectors, choose fixed markers or stable tags, and download the cleaned text. It uses the same engine as the CLI, --config and --key-file work as in the CLI, and nothing is stored or logged.
Safe by construction: the server listens on loopback only unless you pass --allow-remote; it checks the Host header (DNS rebinding) and the Origin / Fetch-Metadata / Content-Type of every request (cross-site POSTs); it limits body size (10 MiB) and concurrency; it sends a strict Content-Security-Policy with no CDN and no inline script or style; and log text is inserted with textContent, never as HTML. Verified in a real browser: an HTML/script payload in a log line stays inert, and the page makes no request outside its own origin.
Engine: matches are now reported as byte spans (Observe); applying them to the input reproduces the output exactly, which the tests and the fuzz target check.
Images: ghcr.io/hbenali/logscrub and docker.io/hbenali/logscrub (identical digest, linux/amd64 and arm64, distroless, non-root).
Docs: README and wiki now have screenshots (light and dark) and a banner; the wiki has Configuration and Web UI pages.
Pattern matching cannot find secrets with no recognisable shape; review the output before sharing it.
0.2.0
Adds personal-data detectors, stable pseudonyms and a config file, and makes scanning about 2.5x faster.
New detectors: email addresses, IPv4 and IPv6 addresses (loopback is left alone), payment card numbers (Luhn-checked, known issuer prefixes), and international phone numbers (off by default: --enable phone). Each has context checks so version strings (Chrome/126.0.0.0), timestamps, MAC addresses, ssh://git@host and icon@2x.png are left untouched; a "must not change" corpus guards them.
Pseudonym mode: --mode pseudonym replaces emails and IPs with stable HMAC-SHA256 tags such as [email:gqgkqsm4], so the same value maps to the same tag across a file and across runs while the log stays debuggable. Secrets keep fixed [REDACTED:id] markers. The key comes from --key-file or LOGSCRUB_KEY (never argv); without one a random per-run key is used.
Config file: --config logscrub.toml takes enable / disable lists, an allow-list (exact values or regexes) and custom RE2 rules. It is parsed strictly. Flags override the file. See the wiki's Configuration page.
Speed: a per-detector prefilter takes a 12.5 MB log from 3.0 s to 1.2 s despite five more detectors. A test and the fuzz target assert it never changes the output.
Dependency: github.com/BurntSushi/toml (no transitive dependencies) for the config file.
Pattern matching cannot find secrets with no recognisable shape; review the output before sharing it.
0.1.0
First release: a CLI that masks secrets and personal data in logs so they can be shared safely.
some-command | logscrub > clean.log, or logscrub app.log.
Detectors: AWS access and secret keys, GitHub / GitLab / Slack / Stripe tokens, JWTs, PEM private keys (including multi-line blocks), Authorization headers and long Bearer tokens, user:password@ in URLs, and password= / token= / "api_key": "..." style pairs.
Modes: --check exits 1 if anything would be masked (for CI); --report prints counts per detector, never the matched text; --enable / --disable select detectors; --max-line-bytes bounds memory.
Design:
- Go's RE2 engine, so crafted input cannot cause ReDoS.
- Streams line by line; a line that cannot be scanned within the memory bound is an error (exit 3), never passed through.
- No network access, no files written, and errors and reports never contain input text.
- A "must not change" corpus of realistic logs guards against false positives; fuzz tests check that nothing maskable is left in the output.
Install: download an archive below (linux, macOS, windows; amd64 and arm64) and check it against checksums.txt, or docker run --rm -i ghcr.io/hbenali/logscrub:0.1.0 < app.log.
Not in this release: emails, IPs, credit cards, stable pseudonyms, a config file and the web UI (planned, see docs/SPEC.md). Pattern matching cannot find secrets with no recognisable shape, so review the output before sharing it.