sherlock-project/sherlock
55.9
Adequate · 18 September 2026
1.4k
lines of production code
Python
primary language
1
measurement over time
What this system is
Sherlock is a username reconnaissance tool that checks the availability of specific usernames across a wide range of social networks and online platforms. It operates as a modular Python package with a command-line interface, supporting both local execution and serverless deployment via Apify. The system maintains an extensive, schema-validated list of supported sites and includes comprehensive testing to ensure accurate detection of user profiles while handling edge cases like NSFW content and Unicode errors.
Features
Automated site listing generation and CI validation summarization
The project now includes scripts to automate the maintenance of the supported sites documentation and improve CI feedback. The new \site-list.py\ script reads the site data, sorts it alphabetically, and generates the \sites.mdx\ documentation file, ensuring the list of supported sites is always up-to-date and correctly formatted. Additionally, \summarize\_site\_validation.py\ parses JUnit XML test results from the CI workflow to produce a human-readable summary table in issue comments, clearly indicating pass/fail status for false-positive and false-negative checks on modified sites.
devel · high confidence
Initial release of Sherlock Actor for Apify
This change introduces the complete definition for the Sherlock Actor on the Apify platform, enabling serverless username reconnaissance across social networks. The addition includes the Dockerfile for the runtime environment, the actor.json manifest, and input/output schemas that allow users to submit a list of usernames and receive found social media links as structured dataset records.
.actor · high confidence
Behavioural changes
Sherlock restructured as a proper Python package with Python 3.9+ requirement
The tool has been refactored from a script-based structure into a standard Python package (sherlock\_project), introducing a \py.typed\ marker file to support PEP 561 type checking. This change enforces a minimum Python version of 3.9, as the entry point now explicitly checks the runtime version and exits if an older interpreter is detected. The internal logic has been modularized into distinct modules for site information, query results, and notifications, providing a more stable foundation for future features.
_sherlock\project · high confidence
Test coverage
Comprehensive test suite for site validation, NSFW handling, and CLI behavior
Added a new pytest-based test suite covering core Sherlock functionality. Tests verify that the site manifest validates against both local and remote JSON schemas, and that site data is iterable with correct error types. Live integration tests check known positive and negative username probes across various sites (e.g., GitHub, GitLab, Docker Hub) and validate that illegal regex patterns are correctly rejected. The suite also includes regression tests for handling Unicode decode/encode errors in username lookups, verifies the NSFW site removal and explicit selection logic, tests wildcard username expansion, and ensures the CLI correctly reports versioning and errors when no usernames are provided.
tests · high confidence
Dependencies
Migration to Poetry build system and Python 3.9+ requirement
The project has switched its build backend from setuptools to Poetry, introducing a pyproject.toml that defines the build system (poetry-core\>=1.2.0) and manages dependencies. This change enforces a minimum Python version of 3.9 (dropping support for 3.8) and updates the dependency specifications, including allowing higher versions for certifi and pandas, while adding dev dependencies like pytest 8.4.2 and pytest-xdist 3.8.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 56.
Lenses
- Code Health 76
- Architecture 69
- Maturity 53
- Readiness 48
- Security 78
Changes since last survey
- 300 commits — 216 feature/other, 84 fixes
By area
- sherlock_project/resources — 126 commits
- (repo) — 108 commits
- .github/workflows — 26 commits
- docs/README.md — 9 commits
- (root) — 7 commits
- sherlock_project/sherlock.py — 6 commits
- sherlock_project/notify.py — 3 commits
- docs/removed-sites.md — 2 commits
- sherlock_project/sites.py — 2 commits
- tests/conftest.py — 2 commits
- tests/test_validate_targets.py — 2 commits
- .actor/README.md — 1 commit
- .github/CODEOWNERS — 1 commit
- devel/site-list.py — 1 commit
- devel/summarize_site_validation.py — 1 commit
- docs/images — 1 commit
- sherlock_project/result.py — 1 commit
- tests/test_ux.py — 1 commit
Notable commits
- fix: fix: Add error messages to BabyRu to prevent false positives
- fix: Fix Cracked Forum false positives
- fix: Fix LessWrong detection Issue #2634
- fix: Fix Minor Capitalization Issue in README.md
- fix: Fix Minor Capitalization Issue in README.md (#2716)
- fix: Fix MuseScore URL endpoint
- fix: Fix akniga false negatives
- fix: Fix command injection vuln
- fix: Fix: false positive for topcoder due to invalid regex
- fix: Merge branch 'master' into fix/babyru-false-positive
- fix: Merge branch 'master' into fix/babyru-false-positive
- fix: Merge branch 'master' into fix/remediate-blitztactics
- fix: Merge pull request #2561 from shreyasNaik0101/fix/remediate-deviantart
- fix: Merge pull request #2564 from shreyasNaik0101/fix/remediate-allmylinks
- fix: Merge pull request #2565 from shreyasNaik0101/fix/remediate-mydramalist
- fix: Merge pull request #2568 from shreyasNaik0101/fix/remediate-blitztactics
- fix: Merge pull request #2570 from shreyasNaik0101/fix/remediate-applediscussions
- fix: Merge pull request #2574 from dollaransh17/fix/http-request-timeouts
- fix: Merge pull request #2582 from dollaransh17/fix/boardgamegeek-false-positive
- fix: Merge pull request #2588 from shreyasNaik0101/fix/correct-ci-diff
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sherlock-project/sherlock was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 376018708c0f6948d3f978a9ae2915024e794654 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.