scan_git_range
Scan commits before pushing to detect exposed secrets like API keys and tokens. Reviews the range from base to head and returns redacted findings.
Instructions
Scan the commits in base..head: by default, what git push would send.
Run this before pushing. With the defaults it scans every commit on the current branch that its upstream does not have yet. If the branch has no upstream, the error says so: pass the branch you will push to as base (for example "origin/main").
Args: repo_path: Absolute path to a git repository (or any path inside one). base: Commits reachable from here are excluded (default "@{upstream}"). head: Last commit to include (default "HEAD"). max_commits: Scan at most this many of the newest commits in the range. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: The standard redacted findings report with a "commit" field on each finding, plus "commits_scanned" and "range".
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| base | No | @{upstream} | |
| head | No | HEAD | |
| repo_path | Yes | ||
| max_commits | No | ||
| max_findings | No |