trufflehog icon indicating copy to clipboard operation
trufflehog copied to clipboard

Find, verify, and analyze leaked credentials

Results 681 trufflehog issues
Sort by recently updated
recently updated
newest added

Added PyMySQL secret detector, answering this issue: https://github.com/trufflesecurity/trufflehog/issues/833

pkg/detectors

📌 **Description** Request to add a LambdaTest detector in TruffleHog for identifying potentially leaked credentials such as username and access key. LambdaTest is a cloud testing platform that uses access...

enhancement
contributions welcomed

## Description Salesforce OAuth2 credentials including the consumer and secret key pair are used to authenticate and authorize applications that need access to Salesforce data. These credentials are part of...

enhancement
contributions welcomed
new detector request

## Description A feature was added after https://github.com/trufflesecurity/trufflehog/issues/2683 that allows scanning for secrets in Commit messages. We have a use case where we want to skip this scan as we...

enhancement
pkg/sources

Hi TruffleHog team, I wanted to ask whether TruffleHog supports scanning for secrets in deleted GitHub objects—such as files or commits that have been removed but are still accessible through...

enhancement
question

### Description: This introduces a latent [GraphQL](https://docs.github.com/en/graphql/guides/introduction-to-graphql) client without making any functional changes. The GraphQL API is required for certain features (e.g., #1906), and it is already being manually called...

## Description Old ArcGIS installs (and directory archives containing files related to them) sometimes contain `proxy.config` files. These are configuration files that are used by ArcGIS to (funnily enough) configure...

enhancement
contributions welcomed
pkg/detectors

### TruffleHog Version ``` trufflehog 3.88.23 ``` ### Trace Output https://gist.github.com/mukesh-dream11/246820fa9d57c4019776f77a51856f67 ### Expected Behavior After `git push`, trufflehog should detect the secret, fail with an error code and thus prevent...

bug

A text-based lockfile (`bun.lock`) was recently added to Bun (to replace the previously used binary `bun.lockb` file). It can be created with `bun install --save-text-lockfile`. (Currently only the nightly builds...

bug

### Description: There are a number of problems with this detector. This Pr attempts to fix some of the glaring issues. e.g., > Verification issue: unexpected HTTP response status 400...