{"repo":"boostsecurityio/bagel","free":true,"listed":false,"github":"https://github.com/boostsecurityio/bagel","clone":"git clone https://github.com/boostsecurityio/bagel.git","description":"bagel, a CLI that inventories security-relevant metadata on developer workstations","language":"Go","stars":192,"topics":["cli","developer","devsecops","endpoint","golang","security","security-scanner","supply-chain","supply-chain-security"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"Bagel Inventory what matters on developer machines—tools, configs, and metadata about secrets —to improve org supply‑chain security without exfiltrating payloads. --- What is it? Bagel is a cross‑platform CLI that inspects developer workstations (macOS, Linux, Windows) and produces a structured report of: Dev tool configurations and risky settings across 9 probes: Git, SSH, npm, environment variables, shell history, cloud credentials (AWS/GCP/Azure), JetBrains IDEs, GitHub CLI, and AI CLI tools. Secret locations (metadata only) : presence of tokens, keys, and credentials in config files, env vars, and history—detected by 8 secret detectors— never the secret values . For detailed documentation on each probe and detector, see the Bagel docs site. Looking for more? If you want a more powerful, enterprise-grade version with the ability to deploy at scale and collect posture information across your entire developer laptop fleet, have a look at the BoostSecurity Developer Endpoint Protection (DEP) product. --- Privacy & Safety by Design No payloads. Ever. Bagel records only metadata (path, owner, perms, timestamps, config flags, key type/length/expiry). Secret values are never included in output or written to disk. Local‑first. Reports are printed to stdout as JSON by default. Minimally intrusive. Read‑only operations; no process injection; no network scanners. Transparent. Every probe is documented and can be toggled via configuration. --- Why run it? Modern supply‑chain risk ofte","default_branch":null,"files":null,"tree":[],"storefront":"/r/boostsecurityio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/boostsecurityio/bagel/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}