Skip to content

Releases: majiayu000/keyspoor

Keyspoor v0.1.3

Choose a tag to compare

@github-actions github-actions released this 04 Oct 06:58
a0dc5d5

Keyspoor now has a complete first-use path: a pinned npm demo with expected
redacted output, setup guides for Codex, Claude Code and Cursor, and a copyable
PR/push workflow that retains reports after failed scans. A native staged Git
hook and reviewed local-baseline examples explain how to introduce scanning
into existing repositories.

The MCP concurrency test no longer assumes filesystem work remains active
long enough for a ping to be one of the first two responses. Dispatch behavior
is checked with a held job queue; the real-process test permits legitimate
completion/cancellation ordering. Scanner production behavior is unchanged.

Release automation now publishes MCP Registry metadata using GitHub OIDC,
advances the maintained v1 scanner Action after package publication, and
checks that public Action on Linux, macOS and Windows. npm registry verification
waits for newly published versions to become visible.

Install the native CLI:

npm install -g keyspoor@0.1.3
# Or: brew install majiayu000/tap/keyspoor
# Or: cargo install keyspoor --version 0.1.3 --locked

Start with the Agent setup guide
or complete CI setup.
Google API Key example literals inherited from the Gitleaks allowlist remain
unchanged; their Firebase example provenance is now documented. They are not
scanner authentication settings and their present validity has not been checked.

Keyspoor v0.1.2

Choose a tag to compare

@github-actions github-actions released this 03 Oct 20:47
6bce73f

Full Changelog: v0.1.1...v0.1.2

Keyspoor v0.1.1

Choose a tag to compare

@github-actions github-actions released this 03 Oct 18:44
eb1df81

Keyspoor is an offline Rust secret scanner for repositories, CI and AI coding agents.

  • 225 default rules with documented provenance; independently implemented scanning core.
  • Files, staged Git contents, local Git history, ZIP/tar/gzip, UTF-16 and Base64.
  • Reusable Rust library, native CLI and read-only MCP server.
  • Redacted JSON, streaming JSONL and SARIF; explicit clean/finding/incomplete exit codes.
  • This release fixes Windows path separators in rule matching.

Install the Rust CLI with cargo install keyspoor --locked. Native binaries cover Linux GNU x64/ARM64, macOS Intel/Apple Silicon and Windows x64. Linux builds use Ubuntu 24.04 and do not target Alpine/musl; see the release guide for compatibility limits.

Check downloads against SHA256SUMS. On Unix, run chmod +x on the downloaded binary before use. Source is Apache-2.0; adapted rule data retains the MIT attribution in THIRD_PARTY_NOTICES (included as a release asset).

Website · English guide · 中文文档 · Rust crate · Benchmarks and limitations

Pre-1.0 Rust APIs may change. Scanning is offline; no live credential verification or cloud connectors. Historical benchmark reports use the former name secret-scan and are not universal speed or accuracy claims.

The npm-format package is available as a release tarball (about 9 MB, all five native targets). Install without lifecycle scripts:

npm install -g https://github.com/majiayu000/keyspoor/releases/download/v0.1.1/keyspoor-0.1.1.tgz --ignore-scripts
keyspoor --version

The package is now published on npm. Install with npm install -g keyspoor or run npx keyspoor --version. The registry tarball updates only the README installation instructions; the five native binaries and launcher match the GitHub-hosted tarball.