ggshield is GitGuardian’s command-line application for finding and preventing hardcoded secrets before code is pushed. It scans local files and repositories, can run as a pre-commit hook or in CI, and supports pre-receive hooks for self-managed version control instances. It can also scan Docker image layers, build arguments, and Dockerfiles. Documentation says it detects more than 600 types of secrets. The CLI is open source, but the secrets detection library behind GitGuardian’s public API is closed source. ggshield works on macOS, Linux, and Windows; standard installation requires Git and a supported, non-end-of-life Python version, except when using standalone packages. It requires an API key for a GitGuardian workspace, and its login command can provision and store a personal access token. Files larger than 1 MB are ignored, and each API call accepts at most 20 documents, with larger scans split across calls. GitGuardian says it stores scan metadata but not scan incidents or secrets in its backend.
Who it is for
ggshield suits developers and teams who want secret scanning in local repositories, pre-commit checks, CI, or self-managed pre-receive hooks. It is also relevant to teams scanning Docker build materials.
What is good
- Detects more than 600 types of secrets.
- Supports local, pre-commit, CI, and pre-receive scanning.
- Can scan Docker layers and build files.
- CLI is open source.
- Starter includes unlimited real-time scanning.
What to know first
- Files larger than 1 MB are ignored.
- API calls accept at most 20 documents.
- Standard installation requires Git and supported Python.
Verdict
ggshield offers several points in the development process to scan for hardcoded secrets, including Docker materials. Note the file-size and per-call limits, as well as the Python and Git requirements for standard installation.
ggshield plans and pricing
All plansCompared on secrets scanning software
- Free plan
- Yes
- Supported VCS
- GitHub, GitLab, Bitbucket, Azure DevOps
- CI/CD scanning
- Yes
- Pre-commit scanning
- Yes
- Pull-request scanning
- Yes
- Push protection
- Yes
- Custom detection rules
- Yes





