Commit Graph
317 Commits
Author SHA1 Message Date
Mustansir Muzaffar c1c5570dd4 support multiple ocr providers 2026-04-06 12:47:36 +05:00
Amaan Ullah e81c0fc099 Add Shopify OAuth Detector (#4738)
* add shopify oauth detector

* embed multipart credential provider

* fix shopifyoauth SSRF: use DetectorHttpClientWithNoLocalAddresses

* remove unnecessary Analysis info
2026-04-01 17:53:42 +05:00
Nabeel Alam bfaa370c78 updated detectors.proto and made protos (#4853) 2026-04-01 10:34:31 +05:00
Muneeb Ullah Khan f9d1850dad [INS-241] Datadogapikey detector (#4627)
* [INS-241] New detector (datadogapikey) for datadog apikeys

* Analyzer updated to cater endpoint

* Added new tests for anlyzers

* Removed print statement

* resolved comments and fixed integration tests.

* resolved comments

* changed cli prompt

* Fixed the comments and added app key validation in analyzer

* renamed regex variable

* Added found verified endpoint to ExtraData

* Clean up Analyze function by removing comments

Removed commented-out code for appKey and endpoint.

* [INS-286] Added support to analyze just the apikey in datadog's analyzer

* fixed linter issue

* fixed comment and introduced snake case to make analyzer code cosistent and also fixed flaky tests

* resolved bugbot comment

* updated protos

* resolve conflicts

* updated protobuffs and resolved bugbot comments

* made regex idiomatic

* fixed ssrf vulnerability

* fixed string formatting
2026-03-11 16:04:51 +05:00
Shahzad Haider 71c48afda8 Added detector for JFrog Artifactory Reference Tokens (#4684)
* added detector for artifactory reference tokens

* add artifactory reference token detector to the no cloud endpoints list

* address mustansir feedback; remove the invalid host deletion

* use detectors.DetectorHttpClientWithNoLocalAddresses instead of common.SaneHttpClient() just like sibling artifactory detector
2026-03-04 16:56:24 +01:00
Muneeb Ullah Khan 4563dde124 [INS-283] Support following symlinks in filesystem source (#4742)
* enabled symlinks with maximum depth support

* resolved concurrency bugs and added maxDepthOption to cli

* Removed visited path map and tracked symlink depth by maintaining a counter variable

* separated symlink scanning from scanDir

* resolved bugbot comments

* introduced hash as a separator to avoid collisions
2026-02-24 20:10:16 +05:00
Mustansir 7c84b27f62 [INS-246] Add Google Gemini API key detector (#4649)
* add google gemini api key detector

* change detector name to google cloud api key, mark as verified if 403 is returned

* add build tags for integration test

* changes in defaults.go

* Revert "changes in defaults.go"

This reverts commit 12e7b6f4aa.

* Revert "change detector name to google cloud api key, mark as verified if 403 is returned"

This reverts commit e46bb29b40.

* revert google cloud api changes, change keyword to gemini, add extra field active_google_key

* use aizasy as keyword instead of gemini

* close response body after draining

* remove \b from regex to support keys that end with -

* add \b to the beginning
2026-02-20 22:00:51 +05:00
meredith 1ffbefcea5 Add workspace_id to Slack Continuous metadata (#4749)
This is needed for EE Slack Continuous feature work, for archi reasons
it needs a change to the message here in OSS.
2026-02-19 09:29:48 -06:00
Brad Larsen c563a0692f Add a new NDJSON / JSONL input source (#4721)
This adds a new input source to TruffleHog, accessible via `trufflehog json-enumerator`.

This input source requires a list of filenames, each of which is an NDJSON-formatted sequence of objects that take one of two forms:

Form 1: `{"data": "utf-8 string", "metadata": <non-null JSON value>}`
Form 2: `{"data_b64": "base64-encoded bytestring", "metadata": <non-null JSON value>}`

The `data` / `data_b64` field specifies the content to be scanned. The `metadata` field is arbitrary, and is simply propagated downstream with scan results from the corresponding content.

Note that although `trufflehog json-enumerator` requires a list of filenames to be given, the NDJSON data that you wish to scan may not need to be first written to disk. On Linux and macOS, at least, you can use shell process substitution to set up a named pipe from a producer process, like `trufflehog json-enumerator <(some-program-that-emits-ndjson)`.
2026-02-17 10:27:57 -05:00
Amaan Ullah 6961f2bace OpenAI Admin Key Detector (#4689)
* restrict openai detector regex to skip admin key

* add openai admin key detector

* fix: add missing hyphen in openai detector regex

* incorporated feedback
added tests to check exclusivity
tightened regexes

* remove redundant comment

* uniformity in openai regex
2026-02-11 11:57:53 +01:00
Mustansir b3b1d4180a [INS-258] Revert includeRepos removal from GitHub source (#4673)
* Revert "Remove include repos (#4469)"

This reverts commit 24c73b0cb6.

* generate protos

* preserve tests for repositories
2026-01-27 19:01:50 +05:00
Shahzad Haider a90798cfbb added service account in google drive credentials for dwd support (#4596) 2025-12-10 20:50:10 +05:00
Mustansir 21211a0e4c add response id and response name to postman metadata (#4555) 2025-12-02 14:59:57 +05:00
Shahzad Haider 71caba8a85 added installation_type field in jira source proto for specifying instalation type (#4564) 2025-11-27 15:48:54 +05:00
Brad LarsenandKashif Khan aade3bff55 Add generic JWT detection and verification (#4441)
This adds a generic detector and verifier for generic JWTs.

This uses regular expressions for detection. Only public key cryptography algorithms are supported. Additionally, OIDC Discovery is attempted against the issuer to fetch the public key for signature verification.

Bonus Cleanup:
* Fix mixed indentation in alchemy test
* Use `strings.ReplaceAll(...)` instead of `strings.Replace(..., -1)`
* Use integer range loop instead of explicit counting loop
* Revise and expand detectors.go comments

---------

Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
2025-11-20 10:39:12 -05:00
Kashif Khan 20dccb6395 Scan all images under a namespace for Docker remote registries (#4514)
* Scan all images under a namespace for Docker remote registries

* improvements

* Resolved charlie's comment

* added logs

* formatted error messages
2025-11-06 15:08:28 +05:00
Kashif Khan 75056d9f73 Updated GDrive proto to support On-Prem Scanning (#4539)
* support on-prem gdrive scanning - first step

* backward compatibility
2025-11-05 14:54:33 +05:00
Jordan Tunstill 24c73b0cb6 Remove include repos (#4469)
* Removed redundant IncludeRepos mentions.

* removed proto for IncludeRepos and remade protos

* removed another instance of includeRepos

* reverted proto removal and

* actually deprecated the field

* ran make protos
2025-10-21 15:28:12 -07:00
joeleonjr bc2cd3e45e Local Git Config Sanitization (#4502)
This commit prevents TruffleHog from executing arbitrary commands located in archived malicious git repositories. Thanks to Adam Reiser at Cisco Talos for pointing this out!

This approach uses Git's recommended best practice for sanitizing untrusted git configs: git clone all local file:// git repos prior to scanning. Executing git clone does not execute any of the potentially malicious git configs in the untrusted repo directory, and the output only includes "safe" default configs, similar to what we see when cloning from remote.

We explored a few other approaches (allowlist, denylist, etc), but those carried lots of complications.

A few notes about how this works:

This only applies to local repositories scanned using the git subcommand.
Remote git targets are not impacted.
Local git targets are now cloned to temp by default prior to scanning. Users can specify a --clone-path argument if they don't want to use the default temp dir. Users can specify --trust-local-git-config if they want to trust the repo as is and bypass cloning.
Local --bare repos are handled appropriately.
This approach knocks out (most...all?) of this class of malicious git config vulnerabilities.
Testing:
There's coverage for most of the new code, including: test cases for the specific issue reported, local bare clones, local repos with staged commits, etc. All are passing.
2025-10-15 14:50:44 -04:00
MustansirandShahzad Haider 26d039c1a9 Proto update to support scanning confluence comments (#4484)
* change in protos to support scanning confluence comments

* rename comment -> commentId

* use snakecase for comment_id

---------

Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
2025-10-08 12:02:49 +05:00
Shahzad Haider 2114e77d56 Fix legacy json flag for Github and Gitlab private repos (#4386)
* fix legacy json flag for gitlab private repos

* some code

* incorporated code from main

* remove cloned repositories after the scan is complete

* enhanced the code

* comment addressed

* changed the approach for persisting the repositories for legacy json printing

* addressed comments; updated the variable names
2025-09-03 11:19:28 +05:00
Nabeel AlamandShahzad Haider b231e11b16 [Feature] Added Detector for the Photoroom API (#4414)
* added detector for the photoroom api

* added photoroom to engine defaults

---------

Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
2025-08-29 14:40:04 +05:00
Kashif Khan 15bc3e59af Added support for additional validation rules in custom detector (#4413)
* Added support for additional validation rules in custom detector

* refactored the approach to support validations for each regex in config

* resolved comments
2025-08-26 16:19:24 +05:00
Kashif Khan 6f36a477c6 Added a dedicated optional flag to ignore gists during scan (#4423)
* Added a dedicated optional flag to ignore gists during scan

* added test case
2025-08-25 16:07:05 +05:00
Kashif Khan 07c16636eb Enable cloning repository to a specified location with retention option (#4408)
* Enabled cloning repositories to a specified path with retention option

* Fixes after testing

* resolved lint issue

* resolved comments

* enabled clone path for github basic auth
2025-08-20 18:10:02 +05:00
Nabeel AlamandAmaan Ullah e819d90e6b [Feature] Updated Dotmailer Detector To Dotdigital (#4331)
* updated dotmailer detector; renamed to dotdigital

* temp

* temp

* updated dotmailer name, verification method and tests

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-08-19 16:18:25 +05:00
Casey Tran 9005cf9826 Added explicit secrets manager write flag to Bitbucket source (#4403)
Added a field in the proto definition for Bitbucket sources to explicitly allow writing to the user's secrets manager. Initially this will be used to keep new and unused Bitbucket refresh tokens inside of the secret that we pull the config from. This process needed to happen in the first place because Bitbucket as an OAuth authorization server currently revokes any previously issued refresh tokens whenever the newest refresh token is issued with an access token, effectively making refresh tokens in the config file single-use.
2025-08-18 09:29:48 -05:00
ab685b0cd6 [Detector] rippling detector for phrase api tokens (#4348)
* add detector for phase OAuth Access Token

* update test cases for phrase AccessTokens

* update integration tests for phrase access token

* resolve comments

* add detector scanner in engine

* resolve comments

* update test cases

* addressed comment about the deduplication of tokens

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
Co-authored-by: Shahzad Haider <shahzadhaider.se@gmail.com>
2025-08-18 18:09:33 +05:00
Casey Tran 0f58ae7c50 Update proto definitions for custom bitbucket oauth (#4390)
Update the proto definitions found for Bitbucket sources to have OAuth option in the config file. Also regenerated the Protobuf files with the changes.
2025-08-14 15:34:14 -05:00
jordanTunstillandAmaan Ullah 0c9fbff428 added User to proto (#4378)
* added User to proto

* ran make protos

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-08-13 08:29:39 -07:00
Dustin Decker 0ebf8ca606 Add option to skip binary files during filesystem source scanning (#4376) 2025-08-08 08:57:53 -07:00
SyedAliHamadandAmaan Ullah d8658ced7d Oss 133 new detector vault approle auth for hashicorp (#4362)
* add detector for hashicorp vault auth

* resolve comments and update test cases

* add indefinite response handling

* resolve comments

* update error response

* resolve merge issues

* follow code convention

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-08-07 20:04:42 +05:00
Charlie Gunyon c53f4d3392 Restore link field in Slack Continuous Source protobuf message (#4360) 2025-08-04 09:42:43 +02:00
2f1baea40d [detector] feat: added rootly detector (#3414)
* [detector] feat: added rootly detector

* [wip]feat: detector rootly

* feat: added correct rootly detector

* feat: added correct unit tests

* feat: added correct unit tests

* feat: added correct unit tests

* feat: added correct unit test

* feat: added `VerificationError` abstraction

Signed-off-by: Sahil Silare <sahilsilare@gmail.com>

* feat: addressed review comments

Signed-off-by: Sahil Silare <sahilsilare@gmail.com>

* Changed verification URL
modified status code handling and added comments
fixed GCP cred access in integration tests

* Refactor HTTP request in Rootly detector to use http.MethodGet and http.NoBody for improved clarity and consistency.

* Incorporated feedback

* fixed missing bracket

---------

Signed-off-by: Sahil Silare <sahilsilare@gmail.com>
Co-authored-by: Aman Ullah <aman.ullah.jalal@trufflesec.com>
Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
2025-08-01 19:24:45 +05:00
Shahzad Haider a95f8bc878 Scan GitLab Groups (#4320)
* gitlab groups init

* added list group projects api

* list group projects updated

* added duplicate repo scan check

* comments addressed

* added error when repo and group id flags are provided at the same time

* added test case for gitlab group projects
2025-07-29 15:14:31 +05:00
SyedAliHamadandAmaan Ullah 05e2328da2 [Detector]-Detector for tableau personal access token (#4261)
* add detector for tableau personal access token

* add test for tableau detector

* removed unnecessary checks

* add cloud endpoint for tableau

* cleanup: simplify map copying with maps.Copy

* resolve comments

* added correct detector type for tableau

* updated tableau PAT key and corrected integration tests

* resolved comments

* updated test cases

* resolved comments

* fixed integration tests

* removed redundant validation

* resolved false positive issue

* updated regex for pat-name

* resolved comments

* update regex for better token name extraction

* simplify prefix regex  for tableau pat name

* merged main into origin/detector/tableau-personal-access-token

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-07-28 21:42:58 +05:00
Charlie Gunyon 6c89e84954 Regenerate protobufs with the correct protoc (etc) version (#4349) 2025-07-28 15:31:07 +02:00
d3459e6fed feat: add webexbot support (#4322)
* feat: add webexbot support

* build proto using make

* remove generic words

* added the secret scanner to the engine defaults

* remove keywords from regex and PR suggestions

* fixed pattern tests

* return err to set on results and remove duplicate keyword

---------

Co-authored-by: Shahzad Haider <shahzadhaider.se@gmail.com>
Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
2025-07-28 10:22:59 +05:00
Charlie Gunyon 227d92c99c Add slack continuous protobuf messages (#4330)
* Add protos for Slack Continuous

* Shrink new proto to only what's required

* Swap private key for project id

* Regenerate protos
2025-07-23 13:51:50 +02:00
Dustin Decker 143f2f562e Add additional Vector configuration options (#4301) 2025-07-21 12:14:27 -07:00
Nabeel AlamandAmaan Ullah bfaddae9b6 Added Anypoint API OAuth2 Detector (#4312)
* added anypoint oauth2 detector

* deleting secret from uniqueSecrets map if id-secret pair is verified

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-07-21 16:31:58 +05:00
Shahzad HaiderandKashif Khan 907ac64fd4 Salesforce Refresh Token Detector (#4295)
* salesforce refresh token init

* added pattern tests for salesforce refresh token detector

* added integration tests for salesforce refresh token detector

* code cleaned

---------

Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
2025-07-17 11:12:55 +05:00
Kashif Khan 9e839e34a6 Updated Detectors Proto (#4294)
* Updated Detectors Proto

* Updated Detectors Proto
2025-07-08 20:50:43 +05:00
Kashif KhanandAmaan Ullah c61749f99f RoninApp Rebranded to Clientary (#4272)
Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
2025-07-02 15:11:30 +05:00
Kashif Khan 94577a840f Deprecated AirTable API Key detector (#4266)
* Deprecated AirTable API Key detector

* removed code files

* removed from defaults
2025-06-30 18:29:30 +05:00
cdb814e42e [Update] Coinbase API Detector Updated (#4202)
* updated coinbase detector; deprecated coinbase_waas detector

* updated coinbase detector integration test

* removed coinbase_waas detector; fixed lint issues

* Update pkg/detectors/coinbase/coinbase.go

Co-authored-by: Amaan Ullah <amaanuj.dev@gmail.com>

* removed coinbase_waas from defaults.go

---------

Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
Co-authored-by: Amaan Ullah <amaanuj.dev@gmail.com>
2025-06-27 16:30:00 +05:00
05866d526e feat [detector]: added hasura detector (#3427)
* [wip] detector feat: added hasura detector

* fix: added tests

* updated hasura detector logic and added tests

* simplified code

* added build tag

* addressed feedback

* simplified code

---------

Co-authored-by: Shahzad Haider <shahzadhaider.se@gmail.com>
Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
2025-06-26 18:11:35 +05:00
50b0a39da0 Feat: bitbucket app (#4214)
* add bitbucket app password scanner

* clean up regex and username pattern logic

* feat: re-intro bitbucket in engine.

* feat: add BitbucketAppPassword detector type to proto files

* Update pkg/detectors/bitbucketapppassword/bitbucketapppassword.go
Co-authored-by: Amaan Ullah <amaanuj.dev@gmail.com>

* refactor(bitbucket): tests (+patterns) ; code cleanup
- add switch{} block + credentialPattern[] for readability
- + tidy nested loops
- reflect codebase conventions in verification scope
- hard drain io.Discard, body.Close on res call in verify func
- intro the patterns test as it was not introoed
- standardize the integration test based off others living in repo

* Update pkg/detectors/bitbucketapppassword/bitbucketapppassword.go

Co-authored-by: Amaan Ullah <amaanuj.dev@gmail.com>

---------

Co-authored-by: Brandon Yan <yanjbrandon@gmail.com>
Co-authored-by: x-stp <x-stp@users.noreply.github.com>
Co-authored-by: Amaan Ullah <aman.ullah.jalal@trufflesec.com>
Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com>
Co-authored-by: Amaan Ullah <amaanuj.dev@gmail.com>
2025-06-24 20:50:10 +05:00
Kashif Khan 62faf2e85e Added LangSmith API Key detector (#4251)
* Added LangSmith API Key detector

* added default in engine
2025-06-23 13:23:10 +05:00
Tanner Jones 053617c834 feat(docker): implement exclude paths functionality (#4057)
Description:
Add support for excluding paths in Docker source scanning:

Add ExcludePaths field to Docker protobuf
Implement path exclusion logic in docker.go
Add comprehensive test coverage for exact and wildcard path matching
Update engine to pass exclude paths configuration
Add CLI support for --exclude-paths flag
The implementation supports:

Exact path matching (e.g., /var/log/test)
Wildcard path matching (e.g., /var/log/test/*)
Multiple exclude paths
Tests ensure proper handling of:

Exact path exclusions
Wildcard exclusions
Edge cases and similar paths
References:
https://github.com/trufflesecurity/trufflehog/issues/2216?utm_source=chatgpt.com
2025-06-06 14:29:22 -04:00