Find, verify, and analyze leaked credentials

27.3K stars 2.5K forks 27.3K watchers Go GNU Affero General Public License v3.0
credentials devsecops dynamic-analysis precommit scanning secret secret-management secrets security security-tools trufflehog verification
10 Open Issues Need Help Last updated: Aug 3, 2026

Open Issues Need Help

View All on GitHub
help wanted contributions welcomed good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
enhancement help wanted contributions welcomed pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
Rancher Tokens 2 months ago
enhancement pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
enhancement pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
help wanted pkg/sources needs-reconciliation

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification

AI Summary: This GitHub issue requests new detectors for Flutterwave API secrets, including secret keys, public keys, passphrases, and webhook signing keys. The request specifies exact key formats with `TEST` or `LIVE` prefixes and a hex-like middle segment, along with common variable names, to be added to the scanning tool.

Complexity: 2/5
enhancement pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
enhancement pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
help wanted pkg/sources

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification
bug contributions welcomed pkg/detectors good first issue

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification

AI Summary: The task is to debug a false positive in TruffleHog, a secrets detection tool. TruffleHog v3.90.3 incorrectly identifies a GitHub repository's zipball URL as a GitHub token. The solution requires investigating why the Github detector is triggering on this specific URL pattern, potentially involving refining the regular expressions or adding exclusion rules within the detector to prevent false positives on valid URLs. This might involve examining the detector's code, testing different scenarios, and potentially contributing a fix to the TruffleHog project.

Complexity: 4/5
enhancement help wanted pkg/detectors

Find, verify, and analyze leaked credentials

Go
#credentials#devsecops#dynamic-analysis#precommit#scanning#secret#secret-management#secrets#security#security-tools#trufflehog#verification