Open-source alpha · v0.3.2

Stop the secret.
Keep the push.

A local Git seatbelt for the moment before code leaves your machine.

Push Guard inspects the committed content you are about to publish, catches likely secrets and private paths, redacts every matched value, and lets Git stop the push. No cloud scanner. No telemetry. No copied credentials.

  • Local only
  • Findings redacted
  • Zero telemetry
  • No target mutation
pre-push

Your final check should protect the secret—not collect another copy of it.

Operating model

One local gate.
Three clear moves.

Push Guard runs as a repository-level pre-push hook or an explicit range scan. It reads through Git, reports only the location and rule that matched, and exits nonzero when review is needed. Git performs the block; your files remain yours.

Read the full security posture
  1. 01
    Inspect the push range

    Scan every introduced commit plus the pushed tip tree for private paths.

  2. 02
    Report without revealing

    Show rule ID, path, line, and reason. Replace the matched value with <redacted>.

  3. 03
    Let Git hold the door

    Exit nonzero so Git blocks publication until the developer reviews the finding.

01

No network calls

The scanner runs locally and sends nothing to Push Guard or any other service.

02

No retained secrets

Matched values are replaced with a literal redaction marker and are not written to a report.

03

No file mutation

Push Guard reads commit data. It does not edit source, rewrite history, or rotate credentials.

04

No false certainty

A clean result is not a security guarantee. Push Guard is a seatbelt, not a certification.

Quick start

Two commands.
One guarded repo.

Install the package, then install the hook from the repository you want to protect. Push Guard refuses to overwrite an unmanaged existing hook.

Install
$ pip install push-guard
Protect the current repository
$ cd /path/to/repository
$ push-guard install
Cloud or manual range scan
$ push-guard scan --repo . \
    --base origin/main --head HEAD

Current coverage

More than token prefixes.

Provider-shaped credentials are only the first layer. Push Guard also watches private path rules and high-signal supply-chain patterns in executable and package metadata.

Likely secrets

GitHub, OpenAI-style, AWS, private-key markers, and long credential assignments.

Private paths

Common credential files plus local, git-ignored patterns tailored to each repository.

Supply-chain signals

Known compromised packages, risky lifecycle shapes, and malicious loader behavior.

Agent-facing traps

High-signal prompt-injection and agentjacking shapes in executable or configuration diffs.

See every current signal in the README

Part of the guard family

One practical gate in a wider defensive toolkit.

Proof, not promises

Small enough to inspect.
Tested enough to trust carefully.

The public repository contains the scanner, install path, tests, limitations, and release history. Start with the code. Verify the behavior. Keep the override for findings you have intentionally reviewed.

Current release v0.3.2

Tagged public package.

Local test gate 64 / 64

Passing on this release checkout.

Secret values retained 0

Findings use <redacted>.

Telemetry calls 0

No project analytics or uploads.

Known limits

Honest at the edges.

01 Pattern matching can miss secrets or flag long non-secret identifiers.

02 It scans committed push ranges, not uncommitted working-tree changes.

03 It does not remove a committed secret or rotate a credential after exposure.

04 git push --no-verify remains available after deliberate human review.

Questions developers ask first

Clear answers before installation.

Does Push Guard upload my repository?

No. It runs locally, uses Git only to read commit data, and makes no network calls.

Will a finding print my secret into the terminal?

No. The matched value is replaced with <redacted>. The output identifies the rule, file, line, and reason so you can inspect locally.

Does it overwrite my existing pre-push hook?

Not by default. Installation refuses an unmanaged existing hook so you can preserve and chain it intentionally.

Can I add private project paths without publishing their names?

Yes. Put local patterns in the git-ignored .push-guard-private-paths file at the repository root.

Does a clean result prove my repository is safe?

No. It is one local publication gate, not a complete secret-management or supply-chain security program.

Before the next push

Keep the review local.

Inspect the source, install it per repository, and let the human remain the final decision-maker.