finds.dev← search

// the find

sobolevn/git-secret

★ 4,057 · Shell · MIT · updated Sep 2026

:busts_in_silhouette: A bash-tool to store your private data inside a git repository.

git-secret is a bash CLI that lets you commit encrypted files into a git repo, decryptable only by people whose GPG public keys you've added to the repo's keyring. It's aimed at small teams who want secrets versioned alongside code without standing up a separate secrets manager like Vault.

Builds on standard GPG rather than custom crypto, so the trust model is well understood. It's genuinely battle-tested — CI runs against alpine, debian with both gnupg1 and gnupg2, fedora, rocky, arch, and ubuntu, and is packaged downstream for brew, apt, yum, AUR, and Alpine. The test suite (bats-core) uses real GPG key fixtures per test user instead of mocking crypto, and the command set mirrors git's own subcommand style (`git secret add/hide/reveal`), so it's low-friction for anyone who already lives in git.

Revoking a person's access just removes their key and re-encrypts going forward — it does not rotate the underlying secret value, and the README itself admits that if someone already copied the plaintext, you're on your own to change it. That's an easy footgun for teams who assume 'removeperson' means the old secret is now safe. It also drags in a real dependency chain (bash 3.2.57+, gawk, sha256sum/shasum with OS-specific shims) that creates platform-specific edge cases rather than being self-contained. And it doesn't abstract away any of GPG's well-known UX pain — key expiration, trust levels, keyring management — so you still need someone on the team who actually understands PGP.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →