Sign inSign up

docker/sbx-kit-gitguardian:latest

Multi-platform
Manifest digest

sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:6234ccbc863da704d5d4523b546e8c110b2f006b308706925afb9508e03f6579

MIXIN

Installs the GitGuardian CLI (ggshield) with proxy-injected API-key auth for api.gitguardian.com and wires it as a Claude Code AI hook, so the agent's actions are scanned for hardcoded secrets automatically - the real key never enters the sandbox.


Arguments
NameRequiredDefaultDescription
versionOptional1.53.0

ggshield release to install



CapabilitiesExpand a row to see its full configuration.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1RequiredGitGuardian API key (from a Personal or Service Account, "scan" scope). Stored on the host; the sandbox only sees a placeholder and the proxy injects the real value on requests to api.gitguardian.com.
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Requiresclaude

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-gitguardian:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠