← LeakWatch

Changelog

What shipped, and when. Not every commit — just what changes what you can do.

2026-09-01
Detection rules moved to a modular, one-file-per-secret engine

Every secret type LeakWatch looks for — over 380 of them — now lives in its own self-contained rule file instead of being spread across separate internal tables. Each one ships with its own test cases, so a bad pattern is caught before it reaches you, not after. Same scans, same results format — this changes how detection is maintained, not what you see.

2026-08-27
Added 2FA to securize your account

You can now require a second factor at sign-in, via a TOTP authenticator app or backup codes, and we kept the recovery flow straightforward if you lose your device. It closes the gap between a strong password and a stolen session, and it is available from your account security settings.

2026-08-25
A CI/CD tab in the dashboard — every pipeline run, and what it found

Past runs of the CI gate now have a home : /dashboard/ci lists each scan your pipeline triggered, most recent first, with how many secrets came back, of which types and severities, on how many bytes, and which API key made the call. Thirty-day totals sit on top. The same list is available to your own tooling as GET /api/v1/scan/history. One clarification that comes with it, because it changes a sentence we had written : your content is still never stored — the diff is scanned in memory and discarded with the response — but the result of a scan now is. Counts only : no diff, no secret value, no line number, ever. Which means the tab can tell you that a build carried a critical AWS key at 09:12, not which key it was ; that was in the API response your job printed. Runs are deleted after 90 days.

2026-08-25
Secret scanning in your CI/CD pipeline, with nothing to install

A build can now refuse a commit that carries an API key, and it takes one HTTPS call to do it : the job posts the diff it is about to merge to POST /api/v1/scan/content, reads a count, and exits non-zero. No action to install from a marketplace, no binary vendored into your runner image — curl and jq, which your CI image already ships. Nothing you send is kept : the diff is scanned in memory and discarded when the response is sent, never written to a database and never forwarded to a third party. Free keys get 50 scans a day and the response says how many are left ; paid plans are unlimited, accept 5 MiB bodies, and get POST /api/v1/scan/batch to scan up to 200 files in a single call. Copy-paste recipes for GitHub Actions, GitLab CI, CircleCI and pre-push hooks are in the CI/CD tab of the documentation.

2026-08-25
API rate limits are now counted per key, as documented

They were counted per IP. On a hosted CI runner, where outbound addresses are shared between everyone using it, that meant unrelated accounts drawing from the same bucket — visible from the outside as 429s with no cause. Each key now carries its own budget, at the rate its plan advertises : 60 requests per minute on Free, 300 on Solo, 1,000 on Team. A key keeps its budget across runners and IP changes, and two keys on one account no longer compete.

2026-08-23
Site scan — we now read what you deployed, not just what you committed

Verify a domain you own (DNS TXT or a file under /.well-known/) and LeakWatch reads what a visitor's browser reads : the HTML, the JavaScript bundles, and the source maps published beside them — where a hardcoded key is still legible long after minification hid it. The same pass flags configuration a server exposes by accident: a /.env served as plain text, a browsable /.git/ directory, a stray SQL dump, a missing CSP, cookies without Secure or HttpOnly. Group a repository and a domain into a project and the report puts the intersection first : a secret found in your history AND still served in production was never rotated. One free site scan every 30 days, on its own quota — it does not consume your deep scan.

2026-08-19
Public status page

status.leakwatch.net shows whether the site, the API, and background scanning are up — probed from outside our own infrastructure, so it stays readable during an outage. Incidents get written up there.

2026-08-17
FAQ on the homepage

Answers to the questions that came up most in outreach : what a lookup actually checks, what a deep scan clones, what OAuth access grants.

2026-08-15
RSS feed and real "last updated" dates for the live leak feed

/leaks now publishes an RSS feed, and its sitemap entry reflects the last actual detection instead of the build date.

2026-08-14
GitHub App covers private repositories

Continuous monitoring through the GitHub App now extends to private repos you explicitly grant it access to, alongside the public firehose.

2026-08-13
GitHub App integration

Install the LeakWatch GitHub App once and manage which repositories it watches from the dashboard, instead of relying only on the public commit firehose.

2026-08-12
Public API v1

A versioned REST API to search detected leaks, manage API keys, and trigger scans programmatically. Documented at /docs.

2026-08-01
Live leak feed

/leaks: every secret detected across public GitHub and GitLab activity, updated in real time, keys masked and repos never disclosed.

2026-07-26
Deep scan

Clone a repository and replay its full git history, all branches — not just the commits the firehose already indexed. One free per month, unlimited on Solo.