prerelease Prerelease 0.3.0 Latest
CerbIA
prerelease Prerelease 0.3.0 Latest

Secret scanner

Detect configured credential patterns and optionally flag unmatched high-entropy values.

Reference
Scanner

cerbia.core.scanners.SecretScanner detects configured credential patterns and, optionally, high-entropy hexadecimal or Base64-like values that do not already match a known pattern.

Parameter Default Meaning

patterns

built-in set

Replacement (name, regex, risk_score) pattern triples.

extra_patterns

null

Pattern triples appended to the selected set.

entropy_detection

false

Enable high-entropy fallback detection.

severity

CRITICAL

Finding severity.

action

BLOCK

Finding action.

content_types

[TEXT, URL, CODE]

Accepted content types.

The scanner returns match spans and the highest detected score. Entropy fallback skips candidates already matched by configured patterns to avoid duplicate findings.

Each custom pattern is a three-value list: display name, regular expression, and risk score. Invalid regular expressions fail when the scanner is constructed, which makes cerbia validate useful for catching configuration errors early.

scanners:
  - scanner: cerbia.core.scanners.SecretScanner
    init_args:
      entropy_detection: true
      extra_patterns:
        - ["Application token", "APP-[A-Z0-9]{16}", 0.9]