SecOps

Git Secret Scanning

The Transit Agent connects to GitHub, GitLab, and Bitbucket repositories and scans commit history and working tree files for exposed credentials. Detection patterns cover API keys, connection strings, private keys, and certificates across 40+ service-specific formats.

When a match is found, the Transit Agent reports it to CoreLink, which creates a finding with repository path, commit SHA, line number, and matched pattern type. Findings can trigger automatic secret rotation if a matching secret exists in the vault.

Git Secret Scanning screenshot

Key Configuration

  • SCM platform and authentication token
  • Repository include / exclude patterns
  • Scan on push vs. scheduled
  • Pattern set selection
  • Auto-rotate on confirmed match
All documentation Question about this? Talk to us