Metadata-Version: 2.5
Name: gforge-python
Version: 0.1.0
Summary: A git firewall: a global pre-commit hook that blocks commits containing secrets (passwords, keys, tokens, .env files) across macOS, Linux, and Windows.
Project-URL: Homepage, https://github.com/mithilai/gforge-python
Project-URL: Repository, https://github.com/mithilai/gforge-python
Project-URL: Issues, https://github.com/mithilai/gforge-python/issues
Project-URL: Changelog, https://github.com/mithilai/gforge-python/releases
Project-URL: Upstream project (original), https://github.com/psspl-gaurang/gforge
Author: Shrey Tandel, Dwij Acharya
Author-email: Gaurang Joshi <gaurangnil@gmail.com>, Mithil Maske <mithilm21@gmail.com>
Maintainer-email: Mithil Maske <mithilm21@gmail.com>
License: Apache License
        Version 2.0, January 2004
        http://www.apache.org/licenses/
        
        TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
        
        1. Definitions.
        
        "License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document.
        
        "Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License.
        
        "Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity.
        
        "You" or "Your" shall mean an individual or Legal Entity exercising permissions granted by this License.
        
        "Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files.
        
        "Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types.
        
        "Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work.
        
        "Derivative Works" shall mean any work, whether in Source or Object form, that is based on or derived from the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For this License, Derivative Works shall not include works that remain separable from, or merely link or bind by name to, the interfaces of the Work and Derivative Works thereof.
        
        "Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems managed by or on behalf of the Licensor for discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution."
        
        "Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work.
        
        2. Grant of Copyright License.
        
        Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form.
        
        3. Grant of Patent License.
        
        Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work. This license applies only to patent claims licensable by such Contributor that are necessarily infringed by their Contribution alone or by combination of their Contribution with the Work to which such Contribution was submitted. If You institute patent litigation against any entity alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
        
        4. Redistribution.
        
        You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions:
        
        (a) You must give any other recipients of the Work or Derivative Works a copy of this License; and
        
        (b) You must cause any modified files to carry prominent notices stating that You changed the files; and
        
        (c) You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
        
        (d) If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License.
        
        You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License.
        
        5. Submission of Contributions.
        
        Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Nothing in this License supersedes or modifies the terms of any separate license agreement You may have executed with Licensor regarding such Contributions.
        
        6. Trademarks.
        
        This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file.
        
        7. Disclaimer of Warranty.
        
        Unless required by applicable law or agreed to in writing, Licensor provides the Work on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.
        
        8. Limitation of Liability.
        
        In no event and under no legal theory, whether in tort, contract, or otherwise, unless required by applicable law or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages arising as a result of this License or out of the use or inability to use the Work, even if such Contributor has been advised of the possibility of such damages.
        
        9. Accepting Warranty or Additional Liability.
        
        While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor because of your accepting any such warranty or additional liability.
        
        END OF TERMS AND CONDITIONS
        
        APPENDIX: How to apply the Apache License to your work.
        
        To apply the Apache License to your work, attach the following boilerplate notice, with the fields enclosed by brackets replaced with your own identifying information. Do not include the brackets. The text should be enclosed in the appropriate comment syntax for the file format. We also recommend that a file or class name and description of purpose be included on the same printed page as the copyright notice for easier identification within third-party archives.
        
        Copyright 2026 Gaurang Joshi <gaurangnil@gmail.com>
        
        Licensed under the Apache License, Version 2.0 (the "License");
        you may not use this file except in compliance with the License.
        You may obtain a copy of the License at
        
        http://www.apache.org/licenses/LICENSE-2.0
        
        Unless required by applicable law or agreed to in writing, software
        distributed under the License is distributed on an "AS IS" BASIS,
        WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
        See the License for the specific language governing permissions and
        limitations under the License.
License-File: LICENSE
License-File: NOTICE
Keywords: cli,core.hookspath,credentials,devsecops,git,git-hooks,githooks,global-hooks,hooks,pre-commit,secret-detection,secret-scanning,secrets,security
Classifier: Development Status :: 4 - Beta
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Operating System :: MacOS
Classifier: Operating System :: Microsoft :: Windows
Classifier: Operating System :: POSIX :: Linux
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.9
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: Implementation :: CPython
Classifier: Topic :: Security
Classifier: Topic :: Software Development :: Version Control :: Git
Classifier: Typing :: Typed
Requires-Python: >=3.9
Provides-Extra: dev
Requires-Dist: build>=1.2; extra == 'dev'
Requires-Dist: mypy>=1.11; extra == 'dev'
Requires-Dist: pytest-cov>=5.0; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff>=0.6; extra == 'dev'
Requires-Dist: twine>=5.1; extra == 'dev'
Description-Content-Type: text/markdown

# GForge (Python)

> **Governance Forge** — an engineering governance platform that helps teams forge
> consistent development standards through Git automation, quality gates, and
> developer tooling.

[![PyPI version](https://img.shields.io/pypi/v/gforge-python.svg)](https://pypi.org/project/gforge-python/)
[![Python versions](https://img.shields.io/pypi/pyversions/gforge-python.svg)](https://pypi.org/project/gforge-python/)
[![platforms](https://img.shields.io/badge/platform-macOS%20%7C%20Linux%20%7C%20Windows-informational)](#cross-platform-support)
[![license](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)

GForge brings engineering standards to the one place every change passes through:
the commit. Its first governance capability is a **secret firewall** — a managed
global Git hook that stops credentials from ever entering your history, on every
repository, across your whole team.

> **This is the Python port of [GForge][upstream].** The idea, the product design,
> and the detection engine are the work of **Gaurang Joshi**, **Shrey Tandel**, and
> **Dwij Acharya**, who built the original together.
> See [Credits and attribution](#credits-and-attribution).

---

## Why GForge

A single leaked API key, database password, or private key in a commit can mean a
production incident, a costly rotation, and a permanent entry in Git history.
Per-project hooks drift, get skipped, or are never installed. GForge makes the
guardrail **global, automatic, and uniform** for every developer and every repo —
so the standard is enforced by default, not by discipline.

## Features

- **Install once, protected everywhere.** Configures Git's global `core.hooksPath`,
  so the firewall applies to every repository on the machine.
- **Deep, layered detection**
  - **`.env` cross-reference** — blocks any staged file that hardcodes a real value
    from your git-ignored `.env` files (the classic "pasted a token out of `.env`").
  - **Provider rules** — 25+ credential shapes: AWS, GitHub/GitLab, Google, Slack,
    Stripe, Twilio, SendGrid, npm, PyPI, OpenAI/Anthropic, PEM private keys, JWTs,
    database URLs, and more.
  - **Generic secrets** — any credential keyword assigned to a hardcoded value
    (`DB_PASSWORD=…`, `password: "…"`, `api_key = "…"`).
  - **Entropy** — high-entropy strings that carry no recognizable name.
- **Low noise by design.** References like `os.environ["DB_PASSWORD"]`,
  f-string interpolation, placeholders, and env templates (`.env.example`) are not
  flagged, so correct code keeps flowing.
- **Never leaks the secret.** Reports only file paths, line numbers, and rule names —
  the matched value is never printed.
- **Encoding-aware.** Handles UTF‑8, UTF‑16, and BOM-prefixed files (e.g. those
  written by PowerShell) so nothing slips through as "binary".
- **gitleaks turbo (optional).** If [gitleaks](https://github.com/gitleaks/gitleaks)
  is on `PATH`, GForge runs it too and merges the findings.
- **Cross-platform, zero runtime dependencies.** Standard library only.

## Requirements

- **Python** 3.9 or newer
- **Git**

## Installation

```bash
pipx install gforge-python   # or: pip install --user gforge-python
gforge install
```

The PyPI project is `gforge-python`; the command it installs is `gforge`.

`gforge install` is the one-time setup step: it writes the managed hook and points
your global `core.hooksPath` at it. From the next commit onward, changes are
scanned for secrets on every repository. Confirm anytime with:

```bash
gforge verify
```

> **Why two steps, unlike the npm original?** Python wheels have no `postinstall`
> hook — pip deliberately runs no package code at install time. Rather than smuggle
> setup into an import side effect, GForge asks for one explicit command. It is also
> the honest boundary: reconfiguring your global Git config is a decision, not a
> side effect of `pip install`.

## Quick start

```bash
# See the current status of your workstation
gforge verify

# Try it — a hardcoded secret is blocked before it can be committed
echo 'DB_PASSWORD=S3cr3t-Value-123' > config.txt
git add config.txt
git commit -m "add config"
# → GForge blocks the commit and names config.txt (the value is never printed)
```

## Commands

```bash
gforge <command> [--force]
```

| Command | Description |
| --- | --- |
| `gforge install` | Upgrade to the latest version (if any) and install the global hooks. |
| `gforge verify` | Read-only health check of the environment and installed hooks. |
| `gforge update` | Upgrade to the latest version (if any) and refresh the hooks. |
| `gforge uninstall` | Remove GForge-owned hooks and restore your previous Git config. |
| `gforge version` | Print the installed version. |
| `gforge help` | Print usage. |

`--force` (with `install`/`update`) reinstalls the latest release even if you are
already on it. GForge never downgrades below your installed version.

## How detection works

The `pre-commit` hook scans only the files staged for the current commit — not the
whole repository — and blocks the commit if any appear to contain a secret. It
reports file paths, line numbers, and rule names, and **never prints the matched
value**. Detection runs several layers in order:

1. **`.env` cross-reference** — the highest-precision signal: values read (in
   memory only) from your git-ignored `.env` files, matched verbatim in staged code.
2. **Provider rules** — fixed credential shapes for the major cloud and SaaS providers.
3. **Generic secrets** — credential keywords assigned to a hardcoded value; smart
   enough to ignore `os.environ[...]`, function calls, f-strings and `${VAR}`
   interpolation, and obvious placeholders.
4. **Entropy** — unnamed high-entropy strings, tuned to skip Git SHAs, UUIDs,
   lockfiles, and file paths (a path is scored per segment, so a long import path
   is not mistaken for a base64 blob).
5. **Secret files** — `.env` (and `.env.*` except templates), `id_rsa`, `*.p12`/`*.pfx`,
   keystores, `.git-credentials`, `.netrc`, and more.

Detection is best-effort and complements — not replaces — good secret hygiene.

## Managing false positives

Maximum coverage occasionally flags something safe. Three escape hatches:

- **Inline:** add a `gforge:allow` (or `gitleaks:allow`) comment on the line.
- **Per-repo:** add a path or pattern to a `.gforgeignore` file at the repo root
  (a `.gitleaksignore` is also honored):

  ```gitignore
  # .gforgeignore
  tests/fixtures/
  ^docs/sample-config\.md$
  ```

- **One-off:** bypass a single commit with `git commit --no-verify`.

## Staying up to date

`gforge update` upgrades the package to the latest published release and refreshes
the hook. GForge also keeps itself current on its own: at most once a day it checks
PyPI in a detached background process (it never delays or blocks a commit),
installs the update, and prints a one-line notice on commit:

```
gforge: v1.2.0 is available (you have v1.1.0). Run: gforge update
```

The background upgrade only runs when the hook's interpreter is the one GForge is
installed into, so it can never install into the wrong environment.

## Configuration

Behavior is controlled entirely through environment variables — there is no config
file to manage.

| Variable | Effect |
| --- | --- |
| `GFORGE_AUTO_UPDATE=0` | Notify only; do not auto-install new versions (default: auto-install on). |
| `GFORGE_NO_SELF_UPDATE=1` | Skip the pip self-upgrade in `install`/`update` (CI / air-gapped). |
| `GFORGE_PYTHON=/path/to/python` | Pin the Python runtime the hook uses. |
| `NO_COLOR=1` | Disable ANSI colour in all output. |

If a repository or the system already defines its own `core.hooksPath` (e.g. Husky,
lefthook, or `pre-commit`), that value shadows GForge in the affected repository;
`gforge verify` warns when it detects this. Your previous global value is recorded
at install time and restored by `gforge uninstall`.

## Cross-platform support

| Platform | Shells |
| --- | --- |
| macOS | Bash, Zsh |
| Linux | Bash |
| Windows | Git Bash, WSL, PowerShell (via Git for Windows) |

The scanner runs on Python; the hook is a small POSIX shell shim that locates a
Python interpreter robustly (including on Git for Windows) and fails closed if it
cannot — a commit is never allowed through unscanned.

## What GForge changes on your machine

GForge is transparent and fully reversible. It touches only your **global** Git
config and a single directory in your home folder:

- `~/.gforge/hooks/` — the managed hook and scanner (`core.hooksPath` points here).
- `~/.gforge/state.json` — records your previous `core.hooksPath` so `uninstall`
  can restore it.
- `~/.gforge/update-check.json` — the once-a-day version-check cache.

`gforge uninstall` removes GForge-owned files and restores your prior configuration.

## Programmatic use

GForge is primarily a CLI, but both the command runner and the detection engine are
importable:

```python
import sys
from gforge import run_cli

result = run_cli(["verify"], sys.stdout, sys.stderr)
sys.exit(result.exit_code)
```

```python
from gforge.scanner import scan_text

findings = scan_text("config.py", 'API_KEY = "s3cr3tValue123"')
for finding in findings:
    print(finding.file, finding.line, finding.rule_id)  # the value is never exposed
```

## Development

```bash
python -m venv .venv
source .venv/bin/activate          # Windows: .venv\Scripts\activate
pip install -e ".[dev]"

pytest                             # run the test suite
ruff check . && ruff format --check .
mypy                               # strict type checking
python -m build                    # build the sdist and wheel
```

## Differences from the Node original

The behaviour of the detection engine is intentionally identical; the differences
are the ones Python's packaging model forces:

| | Node (`npm i -g gforge`) | Python (this port) |
| --- | --- | --- |
| Setup | Automatic via `postinstall` | Explicit `gforge install` |
| Self-upgrade | `npm install -g gforge@latest` | `pip install --upgrade gforge-python` |
| Version source | `package.json` | Installed distribution metadata |
| Package name | `gforge` | `gforge-python` on PyPI, `gforge` to import and run |
| Hook engine | `~/.gforge/hooks/gforge-scan.mjs` | `~/.gforge/hooks/gforge_scan.py` |
| Interpreter preference | `node` from `PATH`, then baked path | Baked path first, then `PATH` |

The interpreter preference is inverted deliberately: any `node` runs the scanner
equally well, but on Python the interpreter recorded at install time is the one
GForge lives in, which keeps self-upgrade targeting the right environment.

## Roadmap

The secret firewall is the first governance capability. Planned directions:

- Additional commit-time quality gates (commit message and branch conventions,
  large-file and merge-conflict guards).
- Shareable, versioned org policy packs.
- Reporting and audit for governance coverage across a team.

## Credits and attribution

**GForge was created by Gaurang Joshi, Shrey Tandel, and Dwij Acharya**, who
contributed to it equally. The original Node.js implementation lives at
**[github.com/psspl-gaurang/gforge][upstream]** and is the source of everything
that makes this tool what it is: the idea, the product design, the command
surface, the layered detection strategy, and the carefully tuned false-positive
heuristics that the test suite here still encodes.

| | |
| --- | --- |
| **Gaurang Joshi** | Original author — [@psspl-gaurang][gaurang] |
| **Shrey Tandel** | Original author |
| **Dwij Acharya** | Original author |

This package is a Python translation of their work, published under the same
Apache-2.0 licence, with the original `NOTICE` reproduced verbatim. It is not a
fork that claims originality — if GForge is useful to you, the credit belongs
upstream.

Thanks to everyone who has contributed to GForge:

<a href="https://github.com/psspl-gaurang/gforge/graphs/contributors">
  <img src="https://contrib.rocks/image?repo=psspl-gaurang/gforge" alt="GForge contributors" />
</a>

## Contributing

Issues and pull requests are welcome. Please run the checks below before
submitting, keep changes focused, and preserve the Apache-2.0 licence header and
the `NOTICE` file.

```bash
pytest
ruff check .
mypy
```

Changes to the detection engine should stay behaviour-compatible with the upstream
Node implementation wherever practical, so a fix in one can be carried to the other.

## Security

To report a vulnerability, follow the process in [SECURITY.md](SECURITY.md). Do not
open a public issue for security reports, and never include real secrets in a report.

## Licence

Licensed under the [Apache License 2.0](LICENSE), the same licence as the upstream
project. Please preserve the [`NOTICE`](NOTICE) file when redistributing.

[upstream]: https://github.com/psspl-gaurang/gforge
[gaurang]: https://github.com/psspl-gaurang
