Skip to content
trufflehog
Vulnerability Scanning
A secrets discovery, classification, validation, and analysis tool that finds leaked credentials in code, chats, wikis, logs, and more.
Go
·
Latest v3.96.0 · 2d ago
Security brief →
Features
-
Discovers secrets across Git repositories, chat platforms (Slack, Discord), wikis (Confluence), logs, API testing tools, object stores, and filesystems.
-
Classifies over 800 secret types, mapping each to its originating service (e.g., AWS, Stripe, Cloudflare, PostgreSQL).
-
Validates found secrets by attempting authentication to confirm if they are active and exploitable.
Review required
v3.96.0
Mixed
·
Dependencies
go-git update + Duo detector
No immediate action
v3.95.9
Mixed
·
OpenRouter + GitHub fix + Registry mirror
Review required
v3.95.8
Breaking risk
·
Auth
RBAC
"unauthorized" removal
Review required
v3.95.7
Bug fix
·
Auth
RBAC
Fix Atlassian UUID typo
Review required
v3.95.6
Mixed
·
Auth
Scanning fixes + PostgreSQL ignores + S3 failure surfacing
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Go
·
Shell
·
Python
View on GitHub
Homepage
Install & Platforms
Install via
brew
docker
shell-script
binary
go
Platforms
linux
macos
arm64
windows
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open