2026 August
5 min
find more secrets expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks what's new slack scanning trufflehog enterprise is now a listed app in the slack marketplace, so scanning a workspace takes a single authorization from integrations instead of registering your own app and assembling scopes by hand messages, threads, and attached files are scanned for credentials and each finding is verified to confirm whether it is still live availability enterprise edition slack continuous message scanning new messages, thread replies, and edits are scanned as they are sent across public channels, private channels the app is invited to, dms, and group dms edited messages are rescanned, so a credential that is pasted and then amended does not slip through, and the app joins new public channels automatically availability enterprise edition historical slack scanning scanning works back through everything that predates the install, including messages, threads, and attached files such as archives, base64 encoded data, binaries, and microsoft office documents include and exclude lists scope which channels are covered, and interrupted scans resume where they left off historical scanning does not cover dms; real time scanning covers those going forward availability enterprise edition 16 new detectors in enterprise scanning enterprise scanning now covers braintrust, cloudflare api token, cloudflare global api key, cloudinary, duffel, duo, gitlab oauth, hashicorp vault token, hashicorp vault batch token, new relic insights insert key, octopus deploy, pganalyze read key, pinecone, red hat pyxis, shippo, and sonarqube cloud most were previously available in open source only; the sonarqube cloud scoped organization token, duo api secret key, and cloudflare detectors are new in both editions this release availability enterprise and open source cloudflare 2026 credential formats the cloudflare api token and global api key detectors recognize the new prefixed credential formats cloudflare is rolling out during 2026, so newly issued cloudflare credentials are caught as customers migrate to them availability enterprise and open source sharepoint historical version scanning sharepoint scanning now covers historical versions of items in generic lists and search driven document libraries, surfacing credentials that were removed from the current version but remain in an earlier one availability enterprise edition improved google drive domain wide delegation support domain wide delegation permits scanning with the access of all users of a domain in one integration, rather than everything a single authorized user can access at a time it's now available through the add integration wizard, for hosted and self hosted scanners availability enterprise edition encrypted private keys are now reported passphrase protected private keys are now reported as findings even when the passphrase cannot be recovered an encrypted key committed to a repository remains a real exposure, and these were previously dropped entirely availability enterprise edition broader android package scanning apk contents are now detected by inspecting the file itself rather than relying on an apk extension, so android packages surfaced through byte stream enumeration are scanned rather than skipped availability enterprise and open source improve response features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration what's new aws credential analysis aws analyze is now available to customers on the analyze sku, showing what an exposed aws credential can actually reach analysis resolves effective permissions, discovers iam role chaining paths, and warns on iam conditions and policy variables that change what a credential can do in practice availability enterprise edition jira auto close configuration configure jira issues to close automatically when their underlying secret is remediated, managed directly in the integration settings rather than through manual follow up remediation history is deduplicated, issue keys persist correctly across streaming notification updates, and duplicate jira ticket ids no longer appear in the ui availability enterprise edition revoke individual shared secrets revoke access to a single shared secret rather than the entire share, giving finer control when a link has been distributed more widely than intended availability enterprise edition expired jwts excluded from findings verified but expired jwts are now dropped at ingestion instead of surfacing as live findings, cutting noise from tokens that carry no remaining risk availability enterprise edition location type filter update the existing location type filter ui on the secrets list page to single popover view with explanation on whatβs being filtered availability enterprise edition ease administration features here simplify ongoing management of the trufflehog platform, including security hardening, performance improvements, and ui enhancements what's new activity log a new top level view of scan events across every source (to replace the legacy issues view in a future release) filter by date range, event, status, source, and actor, with filters stored in the page url so any view can be shared as a link events are append only and record source names as they were at the time, so renaming a source does not rewrite its history availability enterprise edition scan status clarity completed with errors now means a run reached every resource with some failures, while failed means it stopped early β so it is clear whether coverage was complete completion events are evaluated on a cycle and can lag a scan by up to seven minutes, and activity events are retained for 90 days availability enterprise edition scan activity read api scan activity data is available through a read api, so scan failures can be routed into external monitoring and alerting tools instead of being checked by hand in the dashboard api documentation ships alongside it availability enterprise edition source archiving archive a source to stop scanning it while keeping every finding it produced, searchable with triage history intact archive from the three dot menu on a source's row in integrations; archived sources hide by default, and show archived brings them back dimmed and badged archiving requires the admin or editor role and is permanent, while deleting remains available when the integration and its data should both be gone availability enterprise edition verification freezing for archived sources scanning stops immediately when a source is archived, including scans already in flight, on both hosted and self hosted scanners verification freezes only when every source behind a finding is archived β if an active source can still see the secret, it keeps re verifying frozen findings keep their last verification status, carry a verification frozen badge, and are excluded from mttr availability enterprise edition editors can trigger notifications users with the editor role can now trigger notifications, removing an unnecessary dependency on admin level access for routine workflows availability enterprise edition archived sources filtered server side the sources list now filters archived sources on the server, keeping the integration list responsive for organizations with a large number of retired sources availability enterprise edition clearer source configuration fields source configuration fields now use semantic names, making it clearer what each field expects when setting up an integration availability enterprise edition github apps are scanned only once installed github app sources are no longer scanned before the app has actually been installed, eliminating a class of confusing failures on newly created sources availability enterprise edition paginated user audit log the audit log under settings βΊ users now paginates, so deployments with long user histories can page through entries instead of loading them all at once availability enterprise edition infrastructure & reliability rate limited findings are retried, not dropped secret saves that hit a rate limit are now retried instead of discarded, closing a path where a finding could be lost under heavy scan load availability enterprise edition coordinated backoff across concurrent requests concurrent requests sharing a transport now coordinate their 429 and 503 backoff, so a rate limited source recovers in an orderly way instead of retry storming availability enterprise edition large scan metrics no longer dropped scanner metrics payloads that exceed the grpc receive limit are now chunked rather than rejected, restoring visibility into very large scans availability enterprise edition transient failure handling git clones retry on transient network errors, and slack api timeouts retry instead of failing the entire channel scan availability enterprise and open source fixes bug fixes and correctness improvements across detection, response, administration, and infrastructure posthog key format the posthog detector now matches the current 48 character personal api key body in addition to the legacy 43 character format availability enterprise and open source datadog verification errors surfaced the datadog detector now records a verification error when verification fails, rather than reporting a silent negative availability enterprise and open source github app personal repository scanning scanning all installations no longer rejects organization members' personal repositories, closing a coverage gap in multi org github app deployments availability enterprise and open source sharepoint source validation sharepoint sources now validate their configuration up front, catching setup mistakes before a scan starts availability enterprise edition analyzer error visibility huggingface, postgres, and anthropic analyzers now log failures at their origin instead of silently returning empty results availability enterprise and open source