Install ggshield as a pre-commit hook to block secret commits

domain: docs.gitguardian.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install ggshield via pip: pip install ggshield, or via Homebrew on macOS.
  2. Authenticate by running ggshield auth login, which opens a browser flow and stores a token locally; alternatively set GITGUARDIAN_API_KEY in your environment.
  3. Install the hook locally for a single repository with ggshield install -m local, or globally for all repositories with ggshield install -m global.
  4. Verify the hook is active by running git diff --cached | ggshield secret scan pre-commit in the repo and checking for output.
  5. To integrate with the pre-commit framework instead, add an entry referencing the GitGuardian/ggshield repo in your .pre-commit-config.yaml and run pre-commit install.
  6. Test by staging a dummy credential-like string in a file and attempting git commit; ggshield should block the commit and print the finding.

Known gotchas

Related routes

Configure gitleaks and trufflehog for secret scanning with pre-receive and pre-commit hooks
github.com/gitleaks/gitleaks · 6 steps · unrated
Author a custom secret scanning regex pattern at the GitHub organization level, validate it with a dry run, then publish and enable it for push protection
docs.github.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans