For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/code_security/secret_scanning/configuration.md. A documentation index is available at /llms.txt.

Configuration

This product is not supported for your selected Datadog site. ().

By default, Datadog Secret Scanning scans enabled repositories with all rules in the Secrets & Credentials category of Sensitive Data Scanner. You can customize which rules run, modify default rules, and create custom rules on the Code configuration page in SDS.

The rules, scanning groups, and custom rules described on this page are configured in Datadog. A configuration file in your repository adds separate control over which files are scanned. See File configuration.

Scanning groups

There are two scanning groups that configure Secret Scanning rules.

Managed scanning group

The managed scanning group is managed by Datadog’s security team. It automatically receives new rules and updates to rules, and is enabled by default for all organizations.

Managed scanning group

Custom rule scanning group

The custom scanning group is managed by user orgs. You can create and test custom regex rules or add rules from the SDS rules library.

Custom scanning group

Configuring rules

Customizing default rules

To customize the severity and keywords of a managed default rule, hover over the rule and click the pencil icon on the right.

Edit rule

The edit dialog opens.

Edit rule popup

After editing the rule and clicking Update at the bottom right, the modified rule appears as Customized in the managed scanning group.

Customized secret scanning rule in managed group
Customized rules do not automatically receive severity/default keyword updates from Datadog's security team. To restore a rule to its managed state, hover over a customized rule and click the restore icon at the right.

Creating custom rules

To create a custom rule, go to the custom scanning group and click Add scanning rule at the bottom or Add rule at the top right. Create your regex rule, then configure the severity and keywords. After they’re enabled, your repositories are scanned with the new rules on the next commit.

Add rule to custom group

To update a custom rule, hover over the rule and click the pencil icon on the right.

Disabling rules

Disable a rule by clicking the blue toggle on the right.

After a specific rule is disabled, existing findings from that rule are auto-closed in Secret Scanning on the next commit.

File configuration

Rules are configured in Datadog as described in the Configuring rules section. Which files Secret Scanning reads is configured under the secrets key in the Code Security configuration. Define it in Datadog, or in a code-security.datadog.yaml file at the root of your repository.

For information on configuration locations, precedence, and merging, see Code Security Configuration Reference.

The configuration must begin with schema-version: v1.5, followed by a secrets key containing a global-config object. The global-config object controls repository-wide settings:

PropertyTypeDescriptionDefault
only-pathsArrayFile paths or glob patterns. Only matching files are analyzed.None
ignore-pathsArrayFile paths or glob patterns to exclude. Matching files are not analyzed.None
use-gitignoreBooleanWhether to include entries from the .gitignore file in ignore-paths.true
ignore-generated-filesBooleanWhether to include common generated file patterns in ignore-paths.true
max-file-size-kbNumberMaximum file size (in kB) to analyze. Larger files are ignored.10240

Example configuration

schema-version: v1.5
secrets:
  global-config:
    # Only analyze the following paths/files
    only-paths:
      - "src"
      - "**/*.py"
    # Do not analyze the following paths/files
    ignore-paths:
      - "tests"
      - "**/*.lock"
    use-gitignore: true
    ignore-generated-files: true
    max-file-size-kb: 10240