{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/2"}],"enrichment":{"capability":"Scans Git repositories and other sources for leaked credentials, classifying and validating over 800 secret types to identify active security risks.","skillfed_tags":["secrets-scanning","credential-detection","git-audit"],"use_cases":["Audit a Git repository's full history to find accidentally committed API keys or database passwords before they cause a breach.","Scan a GitHub organization's repositories to identify and validate leaked credentials across multiple projects.","Integrate secret detection into CI/CD pipelines to block commits containing unvalidated high-entropy strings.","Classify and analyze discovered secrets to understand which services or accounts are at risk and what permissions they hold.","Generate SARIF output for GitHub Security tab to track credential findings alongside other code scanning results."],"what_it_does":"TruffleHog is a secrets discovery and validation tool that searches through Git repositories and other sources for leaked credentials. It classifies over 800 secret types\u2014including API keys, database passwords, encryption keys, and service-specific credentials\u2014and maps them back to their origin (AWS, Stripe, Cloudflare, Postgres, etc.). For many common credential types, it can validate whether a discovered secret is still active by attempting authentication, distinguishing between historical leaks and present dangers.\n\nThe tool is designed for security teams and developers who need to audit code history, scan organizational repositories, or integrate credential detection into CI/CD pipelines. It outputs findings in multiple formats (plain text, JSON, SARIF) and supports scanning across Git, Jira, Slack, Confluence, and other platforms through its enterprise variant. The open-source version focuses on discovery, classification, and validation of secrets found in Git history and local filesystems.","worth_installing":"Yes, with conditions. Install if you need to audit Git history for leaked credentials and can work around the unclear GNU license terms. The tool is actively maintained on GitHub with strong community adoption, has no runtime dependencies, and detects a broad range of secret types with validation capability. However, verify the GNU license variant's compatibility with your project before committing, and note that the PyPI package has not been updated since 2021-02-05\u2014you may want to use the Docker image or binary releases for the latest features."},"id":"trufflehog","links":{"html":"https://skillfed.io/packages/trufflehog","md":"https://skillfed.io/packages/trufflehog.md","pypi":"https://pypi.org/project/trufflehog/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2021-02-05","license_spdx":null,"license_treatment":"unclear","name":"truffleHog","python_support":"unspecified","summary":"Searches through git repositories for high entropy strings, digging deep into commit history."},"popularity":{"monthly_downloads":137592,"position":11363,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.2.1"}
