VS Code Extensions
Picket

Picket

by willibrandon

Local-first secrets scanning for Azure Pipelines.

Downloads

1

Rating

(0)

Version

0.2.12

Last updated

Aug 14, 2026

Picket is a MIT-licensed secrets scanner for .NET. It provides a Gitleaks-compatible command surface, a Picket-native scanning surface, Native AOT release binaries, dotnet tool packages, and embeddable AOT-safe libraries for rules, scanning, reporting, and endpoint safety.

Tools

Install the command-line scanner:

dotnet tool install --global Picket

Install the interactive terminal report triage companion:

dotnet tool install --global Picket.Tui.Cli

The release archives are direct Native AOT executable downloads. The dotnet tool packages are RID-specific Native AOT NuGet tool packages selected by the .NET CLI during install for Windows, Linux, and macOS x64/Arm64.

Scan staged, unstaged, and untracked non-ignored Git changes together:

picket scan --git-changes . --report-format jsonl --redact=100

Scan a Hugging Face model, dataset, Space, or bucket with a read-only token stored in an environment variable:

picket scan --huggingface-model owner/model --huggingface-token-env HF_TOKEN --report-format jsonl --redact=100

Scan GitLab issues, comments, releases, and release assets:

picket scan --gitlab-project owner/project --gitlab-include-issues --gitlab-include-releases --gitlab-include-release-assets --gitlab-token-env GITLAB_TOKEN --report-format jsonl --redact=100

CI Integrations

Use the Picket Secret Scanner GitHub Action:

- uses: actions/[email protected]
- uses: willibrandon/picket@v0
  with:
    upload-sarif: true

The Action and Azure Pipelines task can also select a Docker archive, OCI archive, or registry image directly, so image-building jobs keep the same Picket reports, redaction, annotations, cache, and failure policy without a separate CLI scan step.

Azure Pipelines can install Picket from the Visual Studio Marketplace and use the PicketScan@1 task:

- task: PicketScan@1
  inputs:
    target: "$(Build.SourcesDirectory)"
    failOn: "findings"

See GitHub Action and Azure DevOps for source selection, permissions, inputs, reports, and failure behavior.

Coding Agent Guards

picket agent guard inspects Codex and Claude PreToolUse and UserPromptSubmit hook events from standard input. It returns 0 for clean input and 2 to block findings or input that could not be safely inspected. See Coding Agent Guards for setup.

Libraries

Picket publishes these embeddable packages:

  • Picket.Rules
  • Picket.Engine
  • Picket.Compat
  • Picket.Report
  • Picket.Security

The public library surface is intentionally narrow and AOT-safe. See docs/EMBEDDING.md for examples and the package roles.

Documentation

Project documentation is published at:

https://willibrandon.github.io/picket/

Related extensions