# BFG Repo-Cleaner vs git-secrets

| Attribute | BFG Repo-Cleaner | git-secrets |
|---|---|---|
| **Vioscale score** | 35.1 (19% (low)) | 40.9 (28% (low)) |
| activity.commits_last_30d | 0 | 0 |
| adoption.dependent_repos | - | 42 |
| adoption.github_stars | 12,175 | 13,380 |
| deployment.options | `{"self_hosted":true}` | `{"on_prem":true}` |
| description.long | A command-line tool that removes large blobs and sensitive data from Git repositories. Distributed as free and open source software under the GNU General Public License. | git-secrets is an open-source command-line utility that integrates with Git as a pre-commit hook to detect and block attempts to commit secrets, API keys, and other sensitive credentials. It uses pattern matching to identify common secret formats and can be customized with additional patterns. |
| integrations.count | - | 1 |
| integrations.list | - | `[{"name":"Git"}]` |
| language.primary | Scala | Shell |
| license.spdx | GPL-3.0 | Apache-2.0 |
| market.availability | - | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true}` | `{"cli":true,"mac":true,"linux":true,"windows":true}` |
| pricing | `{"type":"open_source","summary":"Free and open source","freeTier":true,"sourceUrl":"https://rtyley.github.io/bfg-repo-cleaner","retrievedAt":"2026-08-19T21:34:36.201Z"}` | `{"type":"open_source","summary":"Free and open-source","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-19T21:37:51.446Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | commercial |
| pricing.price_level | free | free |
| pricing.transparent | - | yes |
| release.cadence_days | 118 | - |
| release.history | `[{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.15.0","date":"2025-01-18T21:34:32Z","type":"stable","version":"v1.15.0"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.14.0","date":"2021-02-27T16:46:21Z","type":"stable","version":"v1.14.0"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.13.0","date":"2018-01-31T09:26:15Z","type":"stable","version":"v1.13.0"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.12.5","date":"2015-10-01T22:41:36Z","type":"stable","version":"v1.12.5"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.12.4","date":"2015-08-06T08:58:16Z","type":"stable","version":"v1.12.4"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/git-lfs-alpha","date":"2015-04-09T10:11:24Z","type":"prerelease","version":"git-lfs-alpha"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.12.0","date":"2015-01-01T20:14:58Z","type":"stable","version":"v1.12.0"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.11.5","date":"2014-04-20T14:20:59Z","type":"stable","version":"v1.11.5"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.11.2","date":"2014-03-25T09:49:27Z","type":"stable","version":"v1.11.2"},{"url":"https://github.com/rtyley/bfg-repo-cleaner/releases/tag/v1.11.1","date":"2014-02-01T17:33:31Z","type":"stable","version":"v1.11.1"}]` | - |
| security.scorecard | 2.8 | 5 |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=homebrew&package_name=git-secrets&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (Secrets Scanning)

| Capability | BFG Repo-Cleaner | git-secrets |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Git repository historical scanning | - | - |
| Pre commit developer hooks | - | - |
| Active token validation engine | - | - |
| High entropy regex detection | - | - |
| Slack teams jira scanning | - | - |
| Automated key revocation apis | - | - |
| Custom regex rules support | - | - |
| Ci cd pipeline build blocking | - | - |
| Compliance audit reporting | - | - |
| SOC2 type ii | - | - |
| ISO 27001 | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T15:19:49.666Z. "-" = undocumented, not absent.*
