Guard your code with SailPoint DevGuard (formerly Entro Security DevGuard). This extension scans your files for exposed secrets, API keys, and tokens, helping you prevent security leaks before they happen.
Real-time Secret Scanning: Automatically scans your files as you type or when you open/save them.
SailPoint Entro API Integration: Leverages the SailPoint Entro API for comprehensive secret detection.
Secure Key Storage: Your API key is stored in VS Code's SecretStorage, never in plaintext settings.
Visual Feedback:
Highlighting: Exposed secrets are highlighted directly in the editor.
Hover Details: Hover over a highlighted secret to see details and recommendations.
Status Bar: The status bar reflects scanning activity, findings, and configuration issues.
One-click Actions: A SailPoint DevGuard sidebar (Activity Bar icon) with buttons for scanning and key management, a scan button in the editor toolbar, and a quick-action menu on the status bar item — no Command Palette required.
Right-click Scanning: Scan any file or folder from the Explorer context menu, or the current file from the editor context menu.
Workspace Scanning: Use the SailPoint DevGuard: Scan All Files command to check your entire workspace, with progress and cancellation.
API Key Testing: Use SailPoint DevGuard: Test API Key to verify your key and connectivity before scanning.
Output Logging: Detailed logs are available in the "SailPoint DevGuard" Output Channel.
Requirements
You need a SailPoint Entro API Key for the extension to scan.
Obtain your API Key from the SailPoint Entro dashboard.
Run the SailPoint DevGuard: Set API Key command from the Command Palette (or click the status bar item) and paste your key.
The key is stored securely in VS Code's SecretStorage. If you previously set entro.apiKey in settings.json, the extension will migrate it on first run and clear the plaintext value.
Extension Settings
This extension contributes the following settings (renamed from entro.* in 0.2.0 — existing values migrate automatically):
sailpointDevguard.scanOnType: Scan as you type. Default: true.
sailpointDevguard.advanced.apiDomain: API domain for the SailPoint Entro API. Default: api.entro.security.
sailpointDevguard.advanced.redactSecrets: Whether to redact secrets in the API response. Default: false.
sailpointDevguard.advanced.maxFileSizeBytes: Skip files larger than this when scanning. Default: 1048576 (1 MiB). Hard ceiling: 2621440 (2.5 MiB) — files larger than the ceiling cannot be scanned.
sailpointDevguard.advanced.requestTimeoutSeconds: Timeout for SailPoint Entro API requests, in seconds. Default: 15.
sailpointDevguard.advanced.maxRetries: Retry attempts on timeout or transient network/5xx errors. Default: 2 (max 5).
Commands
SailPoint DevGuard: Set API Key — store/replace your API key in SecretStorage.
SailPoint DevGuard: Test API Key — verify the stored key against the SailPoint Entro API and report the result.
SailPoint DevGuard: Clear API Key — remove the stored API key.
SailPoint DevGuard: Scan for Secrets — manually scan the active document (also in the editor right-click menu). Shows progress and a result notification.
Scan with SailPoint DevGuard — right-click files or folders in the Explorer to scan just that selection.
SailPoint DevGuard: Scan All Files — scan the workspace with live progress (files and findings counts) and cancellation.
SailPoint DevGuard: Show Menu — quick-pick menu with all actions (also opens when clicking the status bar item).
SailPoint DevGuard: Show Log — open the SailPoint DevGuard output channel.
SailPoint DevGuard: Open Settings — jump to the DevGuard settings.
All actions are also available as buttons in the SailPoint DevGuard sidebar (shield icon in the Activity Bar), and the current file can be scanned via the shield button in the editor toolbar.
Known Issues
Files larger than sailpointDevguard.advanced.maxFileSizeBytes are skipped to protect bandwidth and editor responsiveness.