finds.dev← search

// the find

tomnomnom/gf

★ 2,138 · Go · MIT · updated Jun 2024

A wrapper around grep, to help you grep for things

gf is a tiny Go CLI that wraps grep (or ag, or anything else) so you can invoke saved regex patterns by name instead of retyping them. It's aimed at people who run the same grep patterns constantly, most visibly security researchers and bug bounty hunters grepping through crawled JS/HTML for things like PHP sources, AWS keys, or open redirects.

Patterns live as plain JSON files under ~/.gf, so they're trivial to version-control, share, and fork — this is why the security community has built a whole ecosystem of community pattern packs around it. The engine is swappable (grep, ag, etc.) via a single config key, so it doesn't lock you into grep's performance or output format. It ships real shell completion for bash/zsh/fish instead of leaving that as an exercise for the user, which matters a lot for a tool whose whole point is fast interactive use.

The install instructions still say `go get -u`, which has been deprecated since Go 1.17 in favor of `go install` — a small thing but a bad first impression for new users. There's no test file anywhere in the tree for a tool that's essentially string/regex plumbing, so regressions in flag or pattern handling would only surface at runtime. Last push was mid-2024 with no real feature activity since, so it's effectively in maintenance mode — fine if you just want the base tool, but don't expect new engine integrations or pattern management features. The core value (the pattern files) isn't bundled or auto-updated; you're on your own to go find and pull in community pattern repos separately.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →