Creates an opt-in signature registry for common provider credentials plus a contextual high-entropy token check. Values matching an allowlist pattern or obvious placeholders are ignored. Detection never verifies a credential over the network.
Usage
secret_registry(
signatures = NULL,
allowlist = c("(?i)(example|sample|placeholder|dummy|redacted|your[_ -]?(key|token))"),
min_entropy = 3.5,
decoding_depth = 1L,
version = "2026.1",
show_stats = FALSE
)Arguments
- signatures
Optional named character vector of regular expressions.
NULLuses the package registry.- allowlist
Character vector of regular expressions to ignore.
- min_entropy
Minimum Shannon entropy for contextual generic tokens.
- decoding_depth
Maximum bounded URL/base64 decode passes, from 0 to 3.
- version
Registry version recorded with findings.
- show_stats
Show construction time and available usage metrics.
Value
A shieldr_secret_registry object for scanner_options().
Examples
scanners <- scanner_options(secrets = secret_registry())
