Gitleaks is an open-source secret scanner with 27K+ GitHub stars that detects hardcoded passwords, API keys, tokens, and private keys in Git repositories, files, directories, and full Git history. It integrates via GitHub Actions, pre-commit hooks, CI/CD pipelines, and single-binary local scans.
Best Sherlock Alternatives
4 editor-verified alternatives · Sherlock overview →
source: tools.alternatives · stored order · active records only; review scores are annotations and never change membership or order
OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.
Trivy is an open-source vulnerability scanner with 24K+ GitHub stars by Aqua Security that scans container images, file systems, Git repositories, Kubernetes clusters, and IaC configurations for security issues. Detects OS package and language-specific vulnerabilities, misconfigurations, secrets, and license violations in a single tool. Runs as a simple CLI with zero configuration needed. Supports SBOM generation, VEX for vulnerability filtering, and CI/CD integration.
Semgrep is an AppSec platform with a widely used open-source engine for readable code rules plus commercial SAST, supply-chain and secrets workflows. Current product positioning emphasizes AI-assisted detection, triage and remediation, CI/pull-request integration and managed governance for security teams.
Open-source Sherlock alternatives
Gitleaks, osv-scanner, Trivy, Semgrep — see all open-source developer tools.
FAQ
What is the best Sherlock alternative?
Gitleaks tops our editor-verified list of 4 Sherlock alternatives, scoring 84/100 in our hands-on review.
Are there open-source Sherlock alternatives?
Yes — Gitleaks, osv-scanner, Trivy, and more are open source.