Skip to content

trufflehog

Vulnerability Scanning

A secrets discovery, classification, validation, and analysis tool that finds leaked credentials in code, chats, wikis, logs, and more.

Go Latest v3.96.0 · 2d ago Security brief →

Features

  • Discovers secrets across Git repositories, chat platforms (Slack, Discord), wikis (Confluence), logs, API testing tools, object stores, and filesystems.
  • Classifies over 800 secret types, mapping each to its originating service (e.g., AWS, Stripe, Cloudflare, PostgreSQL).
  • Validates found secrets by attempting authentication to confirm if they are active and exploitable.

Recent releases

View all 25 releases →
Review required
v3.96.0 Mixed
Dependencies

go-git update + Duo detector

No immediate action
v3.95.9 Mixed

OpenRouter + GitHub fix + Registry mirror

Review required
v3.95.8 Breaking risk
Auth RBAC

"unauthorized" removal

Review required
v3.95.7 Bug fix
Auth RBAC

Fix Atlassian UUID typo

Review required
v3.95.6 Mixed
Auth

Scanning fixes + PostgreSQL ignores + S3 failure surfacing

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
27,098
Forks
2,498
Languages
Go Shell Python

Install & Platforms

Install via
brew docker shell-script binary go
Platforms
linux macos arm64 windows

Community & Support

Beta — feedback welcome: [email protected]