Best fit
A plausible ignore file can still miss a nested environment file, private key, credential export, or negation that re-includes sensitive material.
Check supplied repository paths and ignore patterns for uncovered or already tracked sensitive-looking files.
A plausible ignore file can still miss a nested environment file, private key, credential export, or negation that re-includes sensitive material.
A plausible ignore file can still miss a nested environment file, private key, credential export, or negation that re-includes sensitive material.
findings.csv with stable codes and record identifiers. review-manifest.csv with every reviewed item.
Filename heuristics cannot detect secrets inside innocently named files.
No. It reads supplied local evidence and writes only to the selected output directory.
No. The packaged checker is deterministic and applies documented rules to the supplied input.
It means no automated finding was produced. The responsible owner still reviews the original source and decides what to do.
Invalid JSON, duplicate identifiers, missing required arrays, and invalid core values fail closed.
Yes. Every finding carries a stable code, record identifier, severity, source, and message.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get Gitignore Coverage Preflight on Agensi