Secret detection
Secret detection runs in the same pass as static analysis, over every file in the clone, so there is nothing separate to switch on.
What it looks for
Two sources run together:
- The community secrets pack from the Semgrep registry.
- Onam's own secret patterns, which work on any file type:
| Pattern | Typical form |
|---|---|
| AWS access key ID | AKIA… |
| AWS secret access key | 40-character key next to an AWS key name |
| Private key block | -----BEGIN … PRIVATE KEY----- |
| GitHub token | ghp_…, gho_… and related prefixes |
| Slack token | xox… |
| Stripe key | sk_live_… |
| Google API key | AIza… |
| Google service-account key | JSON with a private key field |
| Hard-coded JWT | Three base64url segments in source |
| Generic secret assignment | password = "…", secret = "…" and similar |
Findings are tagged CWE-798 (use of hard-coded credentials) and appear with the other static-analysis results.
What it does not do
- No git history. The scan reads the current state of the branch from a shallow clone. A secret committed and later deleted is not found.
- No live verification. Onam does not test whether a detected credential still works.
- No pre-commit hook. Detection happens when a scan runs, not on a developer's machine.
If a secret has ever been pushed, rotate it. Deleting it from the file, or even rewriting history, does not undo the exposure.