{
  "name": "secretloop",
  "displayName": "SecretLoop",
  "description": "SecretLoop detects exposed secrets, verifies whether they are live, and helps developers rotate and remediate them. A GPY Analytics product.",
  "icon": "docs/icon.png",
  "version": "0.1.3",
  "publisher": "gpyanalytics",
  "engines": {
    "vscode": "^1.85.0",
    "node": ">=18.0.0"
  },
  "categories": [
    "Linters",
    "Other"
  ],
  "activationEvents": [
    "onStartupFinished"
  ],
  "main": "./out/extension.js",
  "exports": {
    "./package.json": "./package.json"
  },
  "contributes": {
    "commands": [
      {
        "command": "secretloop.scanWorkspace",
        "title": "SecretLoop: Scan Entire Workspace"
      },
      {
        "command": "secretloop.scanStagedFiles",
        "title": "SecretLoop: Scan Staged Files"
      },
      {
        "command": "secretloop.installPrecommitHook",
        "title": "SecretLoop: Install Pre-commit Hook"
      },
      {
        "command": "secretloop.uninstallPrecommitHook",
        "title": "SecretLoop: Uninstall Pre-commit Hook"
      },
      {
        "command": "secretloop.scanHistory",
        "title": "SecretLoop: Scan Git History for Secrets"
      },
      {
        "command": "secretloop.writeBaseline",
        "title": "SecretLoop: Accept Current Findings as Baseline"
      },
      {
        "command": "secretloop.setAwsAdminCredentials",
        "title": "SecretLoop: Set AWS Admin Credentials for Rotation"
      },
      {
        "command": "secretloop.clearAwsAdminCredentials",
        "title": "SecretLoop: Clear Stored AWS Admin Credentials"
      },
      {
        "command": "secretloop.maskClipboard",
        "title": "SecretLoop: Mask Secrets in Clipboard"
      },
      {
        "command": "secretloop.resetPromptPreferences",
        "title": "SecretLoop: Reset Prompt Preferences"
      }
    ],
    "configuration": {
      "title": "SecretLoop",
      "properties": {
        "secretloop.entropyThreshold": {
          "type": "number",
          "default": 4.3,
          "description": "Shannon entropy threshold above which a string is flagged as a possible secret."
        },
        "secretloop.autoScanOnSave": {
          "type": "boolean",
          "default": true,
          "description": "Automatically scan a file for secrets when it is saved."
        },
        "secretloop.blockCommitOnSecret": {
          "type": "boolean",
          "default": true,
          "description": "Warn in Source Control when staged files contain unresolved secrets."
        },
        "secretloop.envFilePath": {
          "type": "string",
          "default": ".env",
          "description": "File that extracted secrets are moved into."
        },
        "secretloop.enableLiveVerification": {
          "type": "boolean",
          "default": false,
          "description": "Make safe, read-only calls to providers (GitHub, Slack, Stripe, Google, AWS) to confirm whether a detected credential is actually active. Off by default: verification sends the detected credential to a third party, which is not something to do to a repository you have only just opened. SecretLoop offers to turn this on the first time it finds a credential it could check."
        },
        "secretloop.excludePaths": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "default": [],
          "description": "Additional glob patterns never scanned. Added to the built-in list (node_modules, lockfiles, minified bundles), not replacing it."
        },
        "secretloop.entropyPassEnabled": {
          "type": "boolean",
          "default": true,
          "description": "Report generic high-entropy strings that match no known credential format. Turn off if the heuristic tier is too noisy for your codebase; named-format rules keep working."
        }
      }
    }
  },
  "scripts": {
    "compile": "tsc -p ./",
    "watch": "tsc -watch -p ./",
    "pretest": "node scripts/check-build-fresh.js",
    "test": "tsc -p tsconfig.tests.json && ts-node --transpile-only tests/rules.test.ts && ts-node --transpile-only tests/scanner.test.ts && ts-node --transpile-only tests/config.test.ts && ts-node --transpile-only tests/history.test.ts && ts-node --transpile-only tests/report.test.ts && ts-node --transpile-only tests/verify.test.ts && ts-node --transpile-only tests/cli.test.ts && ts-node --transpile-only tests/stubs.test.ts && ts-node --transpile-only tests/remediate.test.ts && ts-node --transpile-only tests/walk.test.ts && ts-node --transpile-only tests/hooks.test.ts && ts-node --transpile-only tests/rotate.test.ts && ts-node --transpile-only tests/harness.test.ts && ts-node --transpile-only tests/fingerprint.test.ts && ts-node --transpile-only tests/extension.test.ts && ts-node --transpile-only tests/settings.test.ts && ts-node --transpile-only tests/workspace.test.ts && ts-node --transpile-only tests/precision.test.ts && ts-node --transpile-only tests/structural.test.ts && ts-node --transpile-only tests/remediation-guidance.test.ts && ts-node --transpile-only tests/review-fixes.test.ts && ts-node --transpile-only tests/detection.test.ts && ts-node --transpile-only tests/fixed-prefix.test.ts && ts-node --transpile-only tests/go-work-sum.test.ts && ts-node --transpile-only tests/containment.test.ts && ts-node --transpile-only tests/fixture-scope.test.ts && ts-node --transpile-only tests/mask.test.ts && ts-node --transpile-only tests/scope-disclosure.test.ts && ts-node --transpile-only tests/build-freshness.test.ts",
    "scan": "ts-node --transpile-only src/cli.ts",
    "bench": "python3 bench/run.py",
    "prepackage": "npm run smoke:vsix",
    "package": "vsce package",
    "prepublish:vsce": "npm run smoke:vsix",
    "publish:vsce": "vsce publish",
    "prepublish:ovsx": "npm run smoke:vsix",
    "publish:ovsx": "ovsx publish",
    "clean": "node -e \"require('fs').rmSync('out',{recursive:true,force:true})\"",
    "bundle": "esbuild src/extension.ts src/cli.ts --bundle --outdir=out --external:vscode --format=cjs --platform=node --minify",
    "vscode:prepublish": "npm run clean && npm run bundle",
    "prepack": "npm run bundle",
    "smoke:tarball": "bash scripts/smoke-tarball.sh",
    "prepublishOnly": "npm run smoke:tarball",
    "smoke:vsix": "bash scripts/smoke-vsix.sh"
  },
  "devDependencies": {
    "@aws-sdk/client-iam": "^3.600.0",
    "@aws-sdk/client-sts": "^3.600.0",
    "@types/node": "^18.0.0",
    "@types/vscode": "^1.85.0",
    "@vscode/vsce": "^3.0.0",
    "esbuild": "^0.28.2",
    "ovsx": "^1.1.1",
    "ts-node": "^10.9.0",
    "typescript": "^5.4.0"
  },
  "keywords": [
    "secretloop",
    "secrets",
    "security",
    "secret-scanning",
    "gitleaks",
    "trufflehog",
    "credentials",
    "api-keys",
    "pre-commit",
    "sarif",
    "devsecops"
  ],
  "license": "MIT",
  "bin": {
    "secretloop": "out/cli.js"
  },
  "repository": {
    "type": "git",
    "url": "git+https://github.com/gpyanalytics/secretloop.git"
  },
  "bugs": {
    "url": "https://github.com/gpyanalytics/secretloop/issues"
  },
  "homepage": "https://github.com/gpyanalytics/secretloop#readme",
  "allowScripts": {
    "esbuild@0.28.2": true
  }
}
