// the find
sobolevn/git-secret
:busts_in_silhouette: A bash-tool to store your private data inside a git repository.
git-secret is a bash CLI that lets you commit encrypted files into a git repo, decryptable only by people whose GPG public keys you've added to the repo's keyring. It's aimed at small teams who want secrets versioned alongside code without standing up a separate secrets manager like Vault.
Builds on standard GPG rather than custom crypto, so the trust model is well understood. It's genuinely battle-tested — CI runs against alpine, debian with both gnupg1 and gnupg2, fedora, rocky, arch, and ubuntu, and is packaged downstream for brew, apt, yum, AUR, and Alpine. The test suite (bats-core) uses real GPG key fixtures per test user instead of mocking crypto, and the command set mirrors git's own subcommand style (`git secret add/hide/reveal`), so it's low-friction for anyone who already lives in git.
Revoking a person's access just removes their key and re-encrypts going forward — it does not rotate the underlying secret value, and the README itself admits that if someone already copied the plaintext, you're on your own to change it. That's an easy footgun for teams who assume 'removeperson' means the old secret is now safe. It also drags in a real dependency chain (bash 3.2.57+, gawk, sha256sum/shasum with OS-specific shims) that creates platform-specific edge cases rather than being self-contained. And it doesn't abstract away any of GPG's well-known UX pain — key expiration, trust levels, keyring management — so you still need someone on the team who actually understands PGP.