SaaSSecurity

Pre-Merge Checks

Block pull requests that introduce API keys, tokens or private keys before they land.

GitHub leaks · 1 credit per leak per lookup · no monthly fee

PR #128Blocked
aws-access-key

How it works

1

Send the repository

Call the GitHub leaks endpoint with a public repository URL. Encrata clones the code and full git history.

2

We scan for secrets

Every commit is scanned for hardcoded API keys, tokens and private keys, including secrets removed in later commits.

3

Rotate what leaked

Get each finding with its file, line and severity, so you can rotate the exposed credentials fast. One credit per leak found.

One call, structured answer

Pre-Merge Checks runs on the github leaks lookup at 1 credit per leak per lookup. Same API key, same JSON shape as every other Encrata lookup.

  • Scans the full git history, not just the current HEAD
  • Finds API keys, tokens and private keys with file and line context
  • A clean repository costs nothing, you only pay per leak found
  • Findings export cleanly into your ticketing and remediation flow
Terminal
curl -X POST "https://developer.encrata.com/api/breaches/github" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"repo": "https://github.com/acme/checkout"}'
response.json
{
"repo": "acme/checkout",
"findings": [
{ "rule": "aws-access-key", "severity": "critical", "path": "config/prod.env", "line": 12 }
],
"credits": 1
}

More github leaks use cases

View all
Start with 500 free credits
$curl https://developer.encrata.com/api/lookup -H "Authorization: Bearer YOUR_API_KEY" -d '{"e": "satya@microsoft.com"}'