Open source · DevOps & Release

Secret Scan Baseline Manager

Maintain an approved secret-scan baseline without hiding new findings.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Read-only checker for local scanner-result and approval-baseline exports. It never scans source, stores secret matches, or rewrites a baseline. Node.js 22+, zero dependencies. src/index.mjs exports auditBaseline(scanner, baseline, policy, {now, deadline}) and TOOLID.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

node bin/secret-scan-baseline-manager.mjs --root examples --policy policy.json --scanner scanner.json --baseline passing-baseline.json
node bin/secret-scan-baseline-manager.mjs --root examples --policy policy.json --scanner scanner.json --baseline failing-baseline.json

Read the result

The synthetic examples exit 0 and 1. --help prints usage to stderr; normal runs print a bounded human summary to stderr. Stdout contains only the v1 JSON report.

Where this check stops

This local walkthrough does not establish the state of a live production system or replace the limits documented in the repository.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.