mirror of
https://github.com/anotherhadi/github-recon.git
synced 2026-10-05 10:58:25 +02:00
@@ -83,20 +83,16 @@ gh-recon --username TARGET_USER [--token YOUR_TOKEN]
|
|||||||
### Flags
|
### Flags
|
||||||
|
|
||||||
```txt
|
```txt
|
||||||
-deep
|
-d, --deep Enable deep scan (clone repos, regex search, analyse licenses, etc.)
|
||||||
Enable deep scan (clone repos, regex search, analyse licenses, etc.)
|
-e, --email string Search accounts by email address
|
||||||
-email string
|
--exclude-repo string Exclude repos from deep scan (comma-separated list)
|
||||||
Search accounts by email address
|
-j, --json string Write results to specified JSON file
|
||||||
-json string
|
--max-size int Limit the size of repositories to scan (in MB) (Only for deep scan) (default 150)
|
||||||
Write results to specified JSON file
|
-c, --only-commits Display only commits with author info
|
||||||
-only-commits
|
-r, --refresh Refresh the cache (deep scan only)
|
||||||
Display only commits with author info
|
-s, --silent Suppress all non-essential output
|
||||||
-silent
|
-t, --token string GitHub personal access token (e.g. ghp_...)
|
||||||
Suppress all non-essential output
|
-u, --username string GitHub username to analyze
|
||||||
-token string
|
|
||||||
GitHub personal access token (e.g. ghp_...)
|
|
||||||
-username string
|
|
||||||
GitHub username to analyze
|
|
||||||
```
|
```
|
||||||
|
|
||||||
## Example
|
## Example
|
||||||
@@ -107,6 +103,21 @@ gh-recon --email [email protected] --token ghp_ABC123...
|
|||||||
gh-recon --username anotherhadi --json output.json --deep
|
gh-recon --username anotherhadi --json output.json --deep
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Cover your tracks
|
||||||
|
|
||||||
|
Understanding what information about you is publicly visible is the first step to managing your online presence. gh-recon can help you identify your own publicly available data on GitHub. Here’s how you can take steps to protect your privacy and security:
|
||||||
|
|
||||||
|
- **Review your public profile**: Regularly check your GitHub profile and repositories to ensure that you are not unintentionally exposing sensitive information.
|
||||||
|
- **Manage email exposure**: Use GitHub's settings to control which email addresses are visible on your profile and in commit history. You can also use a no-reply email address for commits. Delete/modify any sensitive information in your commit history.
|
||||||
|
- **Be Mindful of Repository Content**: Avoid including sensitive information in your repositories, such as API keys, passwords, emails or personal data. Use `.gitignore` to exclude files that contain sensitive information.
|
||||||
|
|
||||||
|
You can also use a tool like [TruffleHog](github.com/trufflesecurity/trufflehog) to scan your repositories specifically for exposed secrets and tokens.
|
||||||
|
|
||||||
|
**Useful links:**
|
||||||
|
|
||||||
|
- [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address)
|
||||||
|
- [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address)
|
||||||
|
|
||||||
## Contributing
|
## Contributing
|
||||||
|
|
||||||
Feel free to contribute! See [CONTRIBUTING.md](CONTRIBUTING.md) for details.
|
Feel free to contribute! See [CONTRIBUTING.md](CONTRIBUTING.md) for details.
|
||||||
|
|||||||
Reference in New Issue
Block a user