Detect-secrets Integration with DefectDojo
detect-secrets is an open-source secrets detection tool developed by Yelp that prevents API keys, passwords, tokens, and other credentials from being committed to source code repositories by scanning code using heuristic regex patterns and Shannon entropy analysis to identify potential secrets before they enter version control. The tool operates through pre-commit hooks and CI/CD pipeline integration with a baseline mechanism that acknowledges existing secrets while preventing new ones from being added, providing an auditing system for developers to review and label findings to maintain high signal-to-noise ratios and minimize false positives.
Data Granularity: What Gets Imported
The following fields are captured from Detect-secrets results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "Detect-secrets",
"engagement": "<engagement-id>",
"file": "results.json"
}