Skip to content

Releases: ryanmurf/shhh

v0.1.1 - Bug Fixes

Choose a tag to compare

@ryanmurf ryanmurf released this 27 Feb 01:40
f0a08ad

shhh-scan v0.1.1

Bug Fixes

  • Fixed invalid JSON output (BUG-020): Context field now strips control characters that could produce unterminated strings, breaking --format json piping to jq and other tools.

  • Fixed PEM header false positives (BUG-019): Private key patterns now require base64 key body after the header. Code that merely references PEM header strings (e.g., .replace("-----BEGIN RSA PRIVATE KEY-----", "")) is no longer flagged as a critical finding.

  • Fixed progress noise in piped output (BUG-021): Progress counter only uses carriage-return updates when stderr is a TTY, preventing garbled output when piping to files or other commands.

v0.1.0 - Initial Release

Choose a tag to compare

@ryanmurf ryanmurf released this 27 Feb 01:25
10ecb6d

shhh-scan v0.1.0

Scan AI coding assistant session files for leaked secrets.

Features

  • 20+ secret detection patterns (AWS, GitHub, Slack, Stripe, SSH keys, etc.)
  • Shannon entropy analysis with 5-layer false positive filtering
  • Auto-discovers Claude, Codex, Copilot sessions (including variant dirs like ~/.claude-hd)
  • Context-aware severity scoring (user_input, ai_output, tool_result, config)
  • Multiple output formats: text, JSON, SARIF, dashboard TUI
  • .shhhignore rule engine for suppressing known false positives
  • Incremental scanning with state persistence
  • Real-time watch mode
  • Secret redaction with backup support
  • Git hook integration (pre-commit/pre-push)
  • Custom rule definitions

Install

npm install -g shhh-scan
shhh scan