No network calls
The scanner runs locally and sends nothing to Push Guard or any other service.
Open-source alpha · v0.3.2
A local Git seatbelt for the moment before code leaves your machine.
Push Guard inspects the committed content you are about to publish, catches likely secrets and private paths, redacts every matched value, and lets Git stop the push. No cloud scanner. No telemetry. No copied credentials.
Your final check should protect the secret—not collect another copy of it.
Operating model
Push Guard runs as a repository-level pre-push hook or an explicit
range scan. It reads through Git, reports only the location and rule that matched,
and exits nonzero when review is needed. Git performs the block; your files remain yours.
Scan every introduced commit plus the pushed tip tree for private paths.
Show rule ID, path, line, and reason. Replace the matched value with <redacted>.
Exit nonzero so Git blocks publication until the developer reviews the finding.
The scanner runs locally and sends nothing to Push Guard or any other service.
Matched values are replaced with a literal redaction marker and are not written to a report.
Push Guard reads commit data. It does not edit source, rewrite history, or rotate credentials.
A clean result is not a security guarantee. Push Guard is a seatbelt, not a certification.
Quick start
Install the package, then install the hook from the repository you want to protect. Push Guard refuses to overwrite an unmanaged existing hook.
$ pip install push-guard
$ cd /path/to/repository
$ push-guard install
$ push-guard scan --repo . \
--base origin/main --head HEAD
Current coverage
Provider-shaped credentials are only the first layer. Push Guard also watches private path rules and high-signal supply-chain patterns in executable and package metadata.
GitHub, OpenAI-style, AWS, private-key markers, and long credential assignments.
Common credential files plus local, git-ignored patterns tailored to each repository.
Known compromised packages, risky lifecycle shapes, and malicious loader behavior.
High-signal prompt-injection and agentjacking shapes in executable or configuration diffs.
Part of the guard family
Proof, not promises
The public repository contains the scanner, install path, tests, limitations, and release history. Start with the code. Verify the behavior. Keep the override for findings you have intentionally reviewed.
Tagged public package.
Passing on this release checkout.
Findings use <redacted>.
No project analytics or uploads.
Known limits
01 Pattern matching can miss secrets or flag long non-secret identifiers.
02 It scans committed push ranges, not uncommitted working-tree changes.
03 It does not remove a committed secret or rotate a credential after exposure.
04 git push --no-verify remains available after deliberate human review.
Questions developers ask first
No. It runs locally, uses Git only to read commit data, and makes no network calls.
No. The matched value is replaced with <redacted>. The output identifies the rule, file, line, and reason so you can inspect locally.
Not by default. Installation refuses an unmanaged existing hook so you can preserve and chain it intentionally.
Yes. Put local patterns in the git-ignored .push-guard-private-paths file at the repository root.
No. It is one local publication gate, not a complete secret-management or supply-chain security program.
Before the next push
Inspect the source, install it per repository, and let the human remain the final decision-maker.