Onam Security

Secret detection

Secret detection runs in the same pass as static analysis, over every file in the clone, so there is nothing separate to switch on.

What it looks for

Two sources run together:

  • The community secrets pack from the Semgrep registry.
  • Onam's own secret patterns, which work on any file type:
PatternTypical form
AWS access key IDAKIA…
AWS secret access key40-character key next to an AWS key name
Private key block-----BEGIN … PRIVATE KEY-----
GitHub tokenghp_…, gho_… and related prefixes
Slack tokenxox…
Stripe keysk_live_…
Google API keyAIza…
Google service-account keyJSON with a private key field
Hard-coded JWTThree base64url segments in source
Generic secret assignmentpassword = "…", secret = "…" and similar

Findings are tagged CWE-798 (use of hard-coded credentials) and appear with the other static-analysis results.

What it does not do

  • No git history. The scan reads the current state of the branch from a shallow clone. A secret committed and later deleted is not found.
  • No live verification. Onam does not test whether a detected credential still works.
  • No pre-commit hook. Detection happens when a scan runs, not on a developer's machine.
If a secret has ever been pushed, rotate it. Deleting it from the file, or even rewriting history, does not undo the exposure.