2026 July
5 min
find more secrets expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks what's new sharepoint generic lists scanning sharepoint sources now scan generic list content, including attachments, with resumption support for interrupted scans this extends coverage beyond standard document libraries into the list based content many organizations use for internal data availability enterprise edition confluence scan coverage improvements confluence scanning now covers all page versions (while skipping purged content), deduplicates space enumeration, trims space names, and handles data center rate limits (http 429) more gracefully duplicate history child scans have also been eliminated availability enterprise edition new detectors braintrust, pganalyze, and red hat pyxis three new detectors expand coverage to braintrust ai evaluation keys, pganalyze database monitoring read keys, and red hat pyxis container registry api keys availability enterprise and open source new detectors octopus deploy new detector for octopus deploy api keys, helping secure ci/cd and release management credentials availability enterprise and open source database detector ignore patterns sql server and postgres detectors now support ignore patterns in enterprise and open source, letting you skip known safe connection strings and reduce verification noise availability enterprise and open source large line file scanning the scanner now handles files with lines exceeding the default 64 kb buffer limit, ensuring secrets in minified or machine generated files are no longer skipped availability enterprise and open source hugging face bucket scanning hugging face sources now scan bucket level storage, extending secret discovery into hugging face model and dataset stores availability open source new detectors openrouter, new relic insights, duffel, shippo, and ipinfo five new detectors expand coverage to openrouter ai gateway keys, new relic insights insert keys, duffel travel booking tokens, shippo shipping platform keys, and ipinfo geolocation keys availability open source improve response features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration what's new multi select triage state filter filter findings by multiple triage states at once instead of one at a time, making it easier to review combined sets such as "unreviewed and in progress " availability enterprise edition faster secret locations api (v3) a new cursor paginated /api/v3/secret locations/ endpoint delivers consistent performance on large tenants, replacing offset based v2 paging that slowed at depth v2 remains available but is deprecated availability enterprise edition azure repos organization validation azure repos sources validate the target organization before starting a scan, catching configuration mistakes early instead of failing mid scan availability enterprise edition active scans sorted by progress in progress scans and jobs now sort by completion percentage, surfacing the scans furthest along at the top availability enterprise edition structured secret parts in scan output scan json output now includes structured secretparts for each finding, giving integrators richer, machine readable context for triage and automation availability enterprise and open source ease administration features here simplify ongoing management of the trufflehog platform, including security hardening, performance improvements, and ui enhancements what's new scanner ip address reference view and programmatically retrieve trufflehog's scanner egress ip addresses — including static nat ips — from the dashboard and external api, simplifying firewall allowlisting for sources that restrict inbound connections availability enterprise edition asynchronous source deletion deleting a large integration no longer blocks the ui or risks out of memory failures deletes return immediately with a "deleting" state while cleanup runs in the background, and in flight scan writes are guarded against sources mid deletion availability enterprise edition jira project include/exclude configure which jira projects to include or exclude directly in the source setup form, giving finer control over scan scope without editing raw configuration availability enterprise edition integration management improvements filter deployed integrations by type, navigate shared secrets via full row clicks, and benefit from predictable case insensitive source search a new source details page scaffold lays the groundwork for richer per integration context availability enterprise edition slack oauth cancellation feedback users who cancel slack authorization now see a clear warning toast instead of landing silently on an ambiguous page availability enterprise edition exclude archived repositories from github org scans github organization scans can now exclude archived repositories, reducing scope and noise for orgs with many inactive repos combining repo with include repos/ exclude repos now returns a clear error instead of silently ignoring filters availability open source github action registry mirror override the trufflehog github action now accepts an image input to override the container image, enabling private registry mirrors for air gapped and mirror based ci environments availability open source fixes bug fixes and correctness improvements across detection, response, administration, and infrastructure scanner fleet recovery the scanner fleet now recovers gracefully from post update api overload, and scanners can start without an update payload, preventing stalls during rollouts availability enterprise edition summary dashboard attribution fix the executive summary's "top remediated integrations" now credits integrations based on current source attribution, fixing missing or double counted entries for rotated secrets availability enterprise edition google sheets full workbook export google sheets scanning now includes all sheets in a workbook rather than only the first, closing a gap where secrets in secondary tabs could be missed availability enterprise edition detector accuracy fixes fixes across several detectors dropbox long lived (sl u ) tokens are no longer truncated before verification; azure sas tokens match regardless of parameter order; the grafana detector correctly flags rotated secrets instead of treating them as valid; confluence uuids no longer surface as false atlassian secrets; the aws detector produces deterministic output; postgres honors ignore tags on default port urls; and the klaviyo detector recognizes the newer key format availability enterprise and open source accurate github app org member scanning github app sources now enumerate organization members using per installation tokens, fixing cross org gaps in multi org app deployments availability enterprise and open source consistent secret redaction redacted secret values in scan output now show the last four characters, matching the admin interface and making it easier to correlate cli findings with the platform ui availability enterprise and open source clearer s3 and cli diagnostics explicitly configured s3 buckets now surface listing and role assumption failures instead of suppressing them, and the scanner avoids terminal capability probes before writing cli output (preventing garbled output in piped environments) availability enterprise and open source