taco-secrets
A secret detection scanner that analyzes SBOM content for leaked credentials, API keys, and other sensitive data.
A secret detection scanner that analyzes SBOM content for leaked credentials, API keys, and other sensitive data.
Overview
| Property | Value |
|---|---|
| Language | Go |
| Framework | Standard library HTTP |
| Port | 8086 (health check) |
| Exposed | Internal only |
| Dependencies | MySQL |
| Repository | tacosec/taco-secrets |
Architecture
taco-secrets is a periodic batch scanner that:
- Polls MySQL for SBOMs that haven't been scanned for secrets (by checking the
secrets_scan_statetable). - Runs regex-based detection rules against the raw SBOM content.
- Masks matched secrets before persisting them -- raw secret values are never stored.
- Records scan state so each SBOM is only scanned once.
Key Packages
| Package | Purpose |
|---|---|
scanner/ | Secret detection engine: rules, scanner, masking, image name extraction |
db/ | MySQL operations: fetch unscanned SBOMs, insert secrets, record scan state |
config/ | Environment variable loading |
Detection Rules
The scanner ships with 10 built-in rules:
| Rule | Severity | Category | Confidence |
|---|---|---|---|
AWS Access Key ID (AKIA...) | Critical | cloud_credential | High |
| AWS Secret Key | Critical | cloud_credential | High |
GitHub Token (ghp_/ghs_) | Critical | api_token | High |
GitLab Token (glpat-) | Critical | api_token | High |
| Generic API Key | Medium | generic_secret | Medium |
| Password in env/config | High | generic_secret | Medium |
| Private Key (RSA/EC/DSA/OPENSSH/PGP) | Critical | private_key | High |
| Database URL with credentials | High | database_url | High |
| Slack Webhook URL | Medium | webhook | High |
| JWT Token | Medium | auth_token | Medium |
Secret Categories
cloud_credential-- AWS, GCP, Azure credentialsapi_token-- GitHub, GitLab, generic API tokensgeneric_secret-- Passwords, secrets, tokens in configprivate_key-- RSA, EC, DSA, OPENSSH, PGP private keysdatabase_url-- Database connection strings with embedded credentialswebhook-- Webhook URLs (Slack, etc.)auth_token-- JWT tokens, session tokens
Masking
All matched secrets are masked before storage. The masker replaces the sensitive portion with asterisks while preserving enough context to identify the secret type. Raw secret values never reach the database.
Distributed Locking
taco-secrets uses MySQL advisory locks (GET_LOCK('taco_secrets', 0)) to prevent concurrent scan cycles when multiple instances are running.
Tables Owned
secrets-- Detected secrets with project_id, sbom_id, namespace, type, severity, category, masked match, confidencesecrets_scan_state-- Tracks which SBOMs have been scanned (sbom_id, findings_count, scanned_at)
Environment Variables
| Variable | Required | Default | Description |
|---|---|---|---|
MYSQL_DSN | Yes | -- | MySQL connection string |
SCAN_INTERVAL | No | 2m | Time between scan cycles |
HEALTH_PORT | No | 8086 | Health check HTTP port |
Health Check
GET /healthz -- Returns 200 OK when MySQL is reachable. Returns 503 if MySQL is down.