Releases: ryanmurf/shhh
Releases · ryanmurf/shhh
Release list
v0.1.1 - Bug Fixes
shhh-scan v0.1.1
Bug Fixes
-
Fixed invalid JSON output (BUG-020): Context field now strips control characters that could produce unterminated strings, breaking
--format jsonpiping tojqand other tools. -
Fixed PEM header false positives (BUG-019): Private key patterns now require base64 key body after the header. Code that merely references PEM header strings (e.g.,
.replace("-----BEGIN RSA PRIVATE KEY-----", "")) is no longer flagged as a critical finding. -
Fixed progress noise in piped output (BUG-021): Progress counter only uses carriage-return updates when stderr is a TTY, preventing garbled output when piping to files or other commands.
v0.1.0 - Initial Release
shhh-scan v0.1.0
Scan AI coding assistant session files for leaked secrets.
Features
- 20+ secret detection patterns (AWS, GitHub, Slack, Stripe, SSH keys, etc.)
- Shannon entropy analysis with 5-layer false positive filtering
- Auto-discovers Claude, Codex, Copilot sessions (including variant dirs like ~/.claude-hd)
- Context-aware severity scoring (user_input, ai_output, tool_result, config)
- Multiple output formats: text, JSON, SARIF, dashboard TUI
- .shhhignore rule engine for suppressing known false positives
- Incremental scanning with state persistence
- Real-time watch mode
- Secret redaction with backup support
- Git hook integration (pre-commit/pre-push)
- Custom rule definitions
Install
npm install -g shhh-scan
shhh scan