Über GitGuardian
GitGuardian is helping developers and security teams secure software development with automated secrets detection & remediation.
We're already using pre-commit for most of our repos so hooking GitGuardian into the process was simple. Since we also already use GitHub, we found integration to be extremely easy.
Unclear how to remove webhooks from my repositories.
Nutzerbewertungen filtern (23)
Nutzung
Sortieren nach
Nutzerbewertungen filtern (23)
Verifizierter Rezensent
GitGuardian Repository Scanning: An Essential Tool
Kommentare: Our primary goal is to ensure secrets aren't accidentally exposed in our repositories, and it's the perfect tool for that!
Vorteile:
GitGuardian is so easy to setup and use. I love how simple it is to analyze your repositories on GitHub and be warned if commits contain secrets.
Nachteile:
The "free" Team pricing requires a manual support process, but it's not that big of a deal.
Fabio
In Betracht gezogene Alternativen:
Fit to purpose to our needs / Very little I need to admin
Kommentare: GitGuardian is now actively included in our core CI/CD pipeline. Setup was very easy and, and the time I need now to admin it is close to zero. After the initial adoption, "avoiding secrets in first instance" is now part of our standard practice. I would say GitGuardian is now our insurance that secrets are not disclosed inadvertently.
Vorteile:
Easy to install. I mean, very easy! I have followed the "Quick-Start" guide, it took me about 30 mins. and when I read "Start Remediating" I thought it was the time to figure out how to adapt to our own environment and I have spent a couple of hours to set-up a manual/parallel integration that was totally unnecessary. I like the remediation flow: no emails back and forth, it simplifies the communication and the resolution of incidents across users. I can easily narrow the scope to what is critical to us, this has reduced the remediation effort to specific and relevant incidents. Automatic notifications: as an admin, I do not need to investigate every and each incident. GitHub Integration: secrets within code are automaticall detected and merge is blocked.
Nachteile:
So many ways to integrate, it might be a plus for others, it was confusing to me. in my case I was not clear if I needed a "VCS/GitHub" or "CI/CD GitHub Actions" integration. Pricing plan for small business is not fully clear and requires to "contact sales".
Chris
Easy to use for GitHub, not so easy for ADO.
Vorteile:
Very easy to setup, simply a few clicks and you're done. Quickly alerts in near real time.
Nachteile:
No support for integrating with ADO, which is frustrating because we've had to purchase another tool for this.
Antwort von GitGuardian
vor 9 Monaten
Hi Chris, Thank you for taking the time to share your experience using GitGuardian. I am happy to learn our product is helping you keep your GitHub repositories secrets free. I also hear you and understand you had a difficult time using GitGuardian with Azure DevOps. While we don't offer a native integration for Azure Repos, the cloud-hosted solution for private Git repos, we do offer a native integration for Azure Pipelines to keep your CI pipelines secrets-free. I would like to offer you a dedicated 1:1 call to walk you through the setup, please drop me an email at ziad.ghalleb@gitguardian.com if you are interested. In addition, we can discuss your needs in terms of secrets scanning capabilities for Azure Repos and see how we can fit these in our 2022 roadmap. Thank you, Ziad
Torgny
In Betracht gezogene Alternativen:
GitGuardian integrates in a snap!
Kommentare: We are using GitGuardian to prevent secrets from leaking into repositories both public and private. So far our experience has been excellent. We actually leaked a private SSH key and got a notification from GitGuardian almost immediately. We were able to revoke the key and remediate the blunder.
Vorteile:
Integration was a snap. We're already using pre-commit for most of our repos so hooking GitGuardian into the process was simple. Since we also already use GitHub, we found integration to be extremely easy.
Nachteile:
We had no issues integrating GitGuardian and have not found any cons, yet.
Antwort von GitGuardian
vor 10 Monaten
Thank you for sharing your experience Torgny! It's great to see teams lay great store by Shift Left and use GitGuardian at the pre-commit level.
Phani
Git the getter
Kommentare: Very satisfied
Vorteile:
The ease of use and ui and features makes me use git guardian daily
Nachteile:
Bugs an atuff can make it harder to use sometimes
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience with GitGuardian Phani. You can help us improve by telling us what went wrong. Please send an email to ziad [dot] ghalleb [at] gitguardian [dot] com detailing the bugs you have encountered and we will be happy to investigate.
Verifizierter Rezensent
GitGuardian the best to maintain a security of the repos in git
Kommentare: It has been great I trust it and the securities of my repos
Vorteile:
It is pretty important to maintain the security of repos. I did not even aware of these until gitGuardian took place in my development.
Nachteile:
I think a more friendly user interface is required to the dashboard of gitGuardian
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience using GitGuardian! If you have any thoughts or ideas on what could make the User Interface friendlier for you, please drop us an email at: ziad [dot] ghalleb [at] gitguardian [dot] com.
Matt
Great product
Kommentare: Very positive, I'll be using it going forward and recommending it
Vorteile:
GitGuardian has already saved my MySQL database and NewRelic accounts, the early alerts are fantastic.
Nachteile:
Nothing really, the alerts are timely and informative, will use it on all my repos.
Antwort von GitGuardian
vor 10 Monaten
Thank you for taking the time to review GitGuardian Matt. We're happy to learn we're protecting critical components such as your database! If you have any feature requests or feedback, drop us an email at contact [at] gitguardian [dot] com.
Verifizierter Rezensent
Feel confident that your developers arn't commiting secrets.
Kommentare: Very positive, I feel more confident now that secrets wont be in git long if they are committed at all. I can trust if I haven't gotten an alert that there are no secrets.
Vorteile:
I like the timely notifications when there is an alert, and the triage for dealing with them are quick and easily understood by users.
Nachteile:
Integration with github more to create issues and pull requests to remove secrets would be nice.
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience using GitGuardian! A greater in-VCS experience is definitely one of the goals we aim towards at GitGuardian. If you want to help us shape the future of this, please drop us an email at: ziad [dot] ghalleb [at] gitguardian [dot] com.
Michael
A+ for GitGuardian
Kommentare: Very happy customer of GitGuardian and use their scans to inform how we manage secrets.
Vorteile:
Love that the product makes it so easy to identify when secrets have been checked into the code! Coupled with the low price point, this is a HUGE win for our team + code base.
Nachteile:
The UI is a little tricky to navigate because there's so much information presented. For example, it's hard for me to figure out how to exclude certain repos from their scans.
Aman
GitGuradian Helps me find the Repos.
Kommentare: I like GitGuradian, although I frequently use it in a week
Vorteile:
Finding a repo which is urgently needed to me It makes easy for me.
Nachteile:
It is a little bit more expensive as compared.
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience Aman! GitGuardian's Internal Repositories Monitoring product is free for Open Source projects, self-employed developers and teams of 25 developers or less.
Eren
Easy to use and very useful
Vorteile:
It is hard to keep track of your projects all the time and GitGuardian does that for you reliably.
Nachteile:
Sometimes you may get spammed with unimportant notifications.
Antwort von GitGuardian
letztes Jahr
Thank you for taking the time to share your experience Eren! GitGuardian's native integrations with the major VCS such as GitHub, GitLab and Bitbucket is what makes tracking all your projects in real-time possible. We're sorry to hear you are receiving many notifications. Have you tried changing the settings in the notifications center to help you focus on secret incidents only?
Akash
My Experience with GitGuardian
Kommentare: I like the experience so far, would love to use it more in the future
Vorteile:
It is very important for developers those are not especially good at keeping those secrets safe.
Nachteile:
More Friendlier UI, for easy management of things.
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience Akash. If you would like to give us more detailed feedback on the UI, please send an email to ziad [dot] ghalleb [at] gitguardian [dot] com.
Deepak
Must use it
Kommentare: I have a habit of keeping file and secret together for simplicity, But many time have pushed those and key and username again and again. I have pushed almost for 7-8 times. Now days i do that mistake rarely but in earlier days I was struggle with this issue
Vorteile:
Scans for secret is the best thing of this software
Nachteile:
There is nothing more we can get from this software. Its absolutely perfect!!!!!... :)
Antwort von GitGuardian
vor 12 Monaten
Thank you for your review Deepak. We are happy GitGuardian is useful to you! Adopting good habits is hard, you can learn more about the best practices for secrets management here - https://bit.ly/3g2pXwS.
joel
The platform at the height of our needs
Vorteile:
Gitguardian is the response to our expectations, since he answered all our preoccupations, both in terms of monitoring and at risk alert
Nachteile:
This platform is really perfect for our cost structure, and in terms of features that's all we needed
Antwort von GitGuardian
letztes Jahr
Thank you for taking the time to share your experience Joel!
Verifizierter Rezensent
Essential tool for modern developers
Vorteile:
Easy to configure and use. Notifies about leaked secrets and potential vulnerabilities in GitHub repos.
Nachteile:
Would be nice to have suggested improvements automated for simple and common mistakes.
Antwort von GitGuardian
vor 11 Monaten
Hi, Thank you for taking the time to share your experience with GitGuardian! We are working on providing more automation and detection at various levels of the development lifecycle, for developers to catch incidents earlier and remediate them faster. If you would like to help us shape future versions of the product, please write to contact [at] gitguardian [dot] com.
Shreyasi
Really a Guardian ...
Kommentare: 5 stars
Vorteile:
The product is easy to use and easily integrable. I love how it alerts me when I have secrets exposed.
Nachteile:
I didn't explore much but I like everything till now ... :)
Antwort von GitGuardian
vor 9 Monaten
Hi, Shreyasi. Thank you for taking the time to share your experience using GitGuardian. We're happy GitGuardian helps you keep secrets out of your code!
Abdisatar
Great Product
Vorteile:
if you were to leak your smtp credentials or env variables accidentally you get notified immediately thus protecting you
Nachteile:
They add a webhook in every repository with no clear way to removing all of them.Rest To Be Determined
Antwort von GitGuardian
vor 9 Monaten
Thank you for sharing your experience Abdisatar! If you want to remove a repository from the real-time monitoring perimeter, go to your workspace Settings > Integrations > VCS integrations and click on "Edit".
Jonathan
Lifesaver for solo or small teams
Vorteile:
Has kept me from pushing private keys to repos and alerted me when I have so I can quickly update. Must have for small teams or solo devs such as myself.
Nachteile:
I don't have any cons, I don't use GitGuardian as much as a very dev heavy team might though.
Antwort von GitGuardian
letztes Jahr
Thank you for your review Jonathan. We're happy to know GitGuardian keeps your repositories secrets free!
Verifizierter Rezensent
A great tool to avoid securities issues
Vorteile:
The real time notification system allowing to control the secrets leak instantly
Nachteile:
At first I was concern about the data Gitguardian has access but I think they manage it pretty clear
Antwort von GitGuardian
letztes Jahr
Thank you for taking the time to share your experience. Our goal is to help you get to your leaked secrets before anyone else does! As for your valid concern on data privacy, GitGuardian's APIs are stateless and do not store any of the documents you send through. We also offer an on-premises version of the Internal Repositories Monitoring for companies with strong privacy requirements.
Verifizierter Rezensent
Exactly as Expected
Vorteile:
It's easy to use and documentation is concise and straightforward
Nachteile:
Oftentimes can feel like it is used in niche cases but it more pertinent than expected
Antwort von GitGuardian
letztes Jahr
Thank you for taking the time to share your experience using GitGuardian. Internal Repositories Monitoring scans your code repositories and alerts you in real-time, you never know!
John
Protector of all things Coded.
Kommentare: I'm new to GitGuardian and a CS student in college. That being said, I'm prone to accidentally commenting security keys in code and forgetting to delete them before commit. The GitGuardian tool has been assisting me in ensuring my recent project applications are not exposed and the easy integration is a big plus.
Vorteile:
Git Secret Detection and Incident report.
Nachteile:
None I can think of yet. But with time there will be additional features that can help ensure optimal security during development. Like some sort of integration in VS Code itself.
Antwort von GitGuardian
vor 12 Monaten
Thank you for taking the time to review GitGuardian John. We're happy to learn GitGuardian is protecting your university CS projects and hope it will be just as helpful when you start your career in software engineering!
Konstantin
GitGuardian Review
Vorteile:
It is very intuitive in set up and use of dashboards. Lots of documentation available and it feels like a very reliable tool
Nachteile:
I didn't find it easy to contact a support line
Hakan
Helpful for lazy people
Vorteile:
It's very common to let Firebase keys leak so i like that it catches them
Nachteile:
Unclear how to remove webhooks from my repositories
Antwort von GitGuardian
letztes Jahr
Thank you for sharing your experience Hakan. If you need any help configuring your custom webhooks, please send an email to: ziad [dot] ghalleb [at] gitguardian [dot] com.