
ggshield
Summary
ggshield is GitGuardian's command-line application for finding and preventing hardcoded secrets before code is pushed. It scans local files and repositories, can run as a pre-commit hook or in CI, and supports pre-receive hooks for self-managed version control instances. It can also inspect Docker image layers, build arguments, and Dockerfiles. Documentation says it detects more than 600 types of secrets. The CLI is open source, though the secrets detection library behind GitGuardian's public API is closed source. ggshield works on macOS, Linux, and Windows, as well as API and self-hosted setups. Standard installation requires Git and a supported, non-end-of-life Python version; standalone packages are an exception. Authentication uses an API key for a GitGuardian workspace, and its login command can provision and store a personal access token. Files larger than 1 MB are ignored, and each API call accepts at most 20 documents, with larger scans split across calls. GitGuardian says it retains scan metadata but not scan incidents or secrets in its backend.
Who it is for
It suits developers and teams who want to scan code repositories, commit workflows, CI pipelines, or Docker files for hardcoded secrets. Self-managed version-control operators can also use its pre-receive hook.
What is good
- Detects more than 600 types of secrets
- Scans local files, repositories, CI, and pre-commit workflows
- Can scan Docker image layers and Dockerfiles
- Open-source CLI
- Free Starter plan includes unlimited real-time scanning
What to know first
- Files larger than 1 MB are ignored
- API calls accept at most 20 documents
- Standard installation requires Git and supported Python
- Requires a GitGuardian workspace API key
Verdict
ggshield offers several points in a development workflow for secret scanning, including repositories, CI, and Docker artifacts. Note the file-size and per-call limits, plus the distinction between its open-source CLI and closed-source detection library.
ggshield plans and pricing
All plansCompared on secrets scanning software
- Free plan
- Yesgitguardian.com
- Supported VCS
- GitHub, GitLab, Bitbucket, Azure DevOpsgitguardian.com
- CI/CD scanning
- Yesgitguardian.com
- Pre-commit scanning
- Yesgitguardian.com
- Pull-request scanning
- Yesgitguardian.com
- Push protection
- Yesgitguardian.com
- Custom detection rules
- Yesgitguardian.com
Facts
- Purpose
- ggshield is GitGuardian’s command-line application for detecting and preventing hardcoded secrets before code is pushed.gitguardian.com · 29 Sept 2026
- Detection
- The documentation says ggshield detects more than 600 types of secrets.docs.gitguardian.com · 29 Sept 2026
- Scanning
- ggshield can scan local files and repositories, run as a pre-commit hook, run in CI, and run in a pre-receive hook for self-managed version control instances.docs.gitguardian.com · 29 Sept 2026
- Docker
- ggshield can scan Docker image layers, build arguments, and Dockerfiles for hardcoded secrets.gitguardian.com · 29 Sept 2026
- Open source
- The ggshield CLI is open source, while the secrets detection library behind GitGuardian’s public API is closed source.gitguardian.com · 29 Sept 2026
- Scan data
- For ggshield scans, GitGuardian says it stores metadata such as call time, request size, and scan mode, while scan incidents and secrets are not stored in its backend.gitguardian.com · 29 Sept 2026
- Authentication
- ggshield requires an API key to authenticate with a GitGuardian workspace, and its login command can provision and store a personal access token.docs.gitguardian.com · 29 Sept 2026
- CI integrations
- The product page describes CI/CD pipeline use and displays Travis CI and Jenkins logos.gitguardian.com · 29 Sept 2026
- Operating systems
- ggshield works on macOS, Linux, and Windows; the standard installation requires a supported, non-end-of-life Python version and Git, except when using standalone packages.docs.gitguardian.com · 29 Sept 2026
- Scanning limit
- Files larger than 1 MB are ignored, and the API accepts at most 20 documents per call, bundling larger scans into multiple calls.docs.gitguardian.com · 29 Sept 2026
- Support
- GitGuardian directs users to the official GitHub repository to report bugs or request features.gitguardian.com · 29 Sept 2026
- Security compliance
- GitGuardian says it has maintained SOC 2 Type II compliance since 2022 and undergoes annual audits.gitguardian.com · 29 Sept 2026
- Company
- GitGuardian says it was founded in Paris in November 2017.gitguardian.com · 29 Sept 2026
Company
- Founded
- 2017gitguardian.com · 28 Sept 2026
- Headquarters
- Paris, Francegitguardian.com · 28 Sept 2026
Best ggshield alternatives
See all 12Where it ranks on Everything Xiaomi
Is ggshield yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- gitguardian.com/ggshield· checked 29 Sept 2026
- docs.gitguardian.com/ggshield-docs/getting-started· checked 29 Sept 2026
- docs.gitguardian.com/ggshield-docs/configuration· checked 29 Sept 2026
- gitguardian.com/legal/public-security-policy· checked 29 Sept 2026
- gitguardian.com/about-us· checked 29 Sept 2026
- gitguardian.com/pricing· checked 29 Sept 2026




