2026 July
5 min
Find More Secrets
Expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks.
What's New
- SharePoint Generic Lists Scanning SharePoint sources now scan generic list content, including attachments, with resumption support for interrupted scans. This extends coverage beyond standard document libraries into the list-based content many organizations use for internal data.
- Availability: Enterprise Edition
- Confluence Scan Coverage Improvements Confluence scanning now covers all page versions (while skipping purged content), deduplicates space enumeration, trims space names, and handles Data Center rate limits (HTTP 429) more gracefully. Duplicate history child-scans have also been eliminated.
- Availability: Enterprise Edition
- New Detectors: Braintrust, Pganalyze, and Red Hat Pyxis Three new detectors expand coverage to Braintrust AI evaluation keys, pganalyze database-monitoring read keys, and Red Hat Pyxis container-registry API keys.
- Availability: Enterprise and Open Source
- New Detectors: Octopus Deploy New detector for Octopus Deploy API keys, helping secure CI/CD and release-management credentials.
- Availability: Enterprise and Open Source
- Database Detector Ignore Patterns SQL Server and Postgres detectors now support ignore patterns in Enterprise and Open Source, letting you skip known-safe connection strings and reduce verification noise.
- Availability: Enterprise and Open Source
- Large-Line File Scanning The scanner now handles files with lines exceeding the default 64 KB buffer limit, ensuring secrets in minified or machine-generated files are no longer skipped.
- Availability: Enterprise and Open Source
- Hugging Face Bucket Scanning Hugging Face sources now scan bucket-level storage, extending secret discovery into Hugging Face model and dataset stores.
- Availability: Open Source
- New Detectors: OpenRouter, New Relic Insights, Duffel, Shippo, and IPinfo Five new detectors expand coverage to OpenRouter AI-gateway keys, New Relic Insights insert keys, Duffel travel-booking tokens, Shippo shipping-platform keys, and IPinfo geolocation keys.
- Availability: Open Source
Improve Response
Features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration.
What's New
- Multi-Select Triage State Filter Filter findings by multiple triage states at once instead of one at a time, making it easier to review combined sets such as "unreviewed and in progress."
- Availability: Enterprise Edition
- Faster Secret Locations API (v3) A new cursor-paginated /api/v3/secret_locations/ endpoint delivers consistent performance on large tenants, replacing offset-based v2 paging that slowed at depth. v2 remains available but is deprecated.
- Availability: Enterprise Edition
- Azure Repos Organization Validation Azure Repos sources validate the target organization before starting a scan, catching configuration mistakes early instead of failing mid-scan.
- Availability: Enterprise Edition
- Active Scans Sorted by Progress In-progress scans and jobs now sort by completion percentage, surfacing the scans furthest along at the top.
- Availability: Enterprise Edition
- Structured Secret Parts in Scan Output Scan JSON output now includes structured SecretParts for each finding, giving integrators richer, machine-readable context for triage and automation.
- Availability: Enterprise and Open Source
Ease Administration
Features here simplify ongoing management of the TruffleHog platform, including security hardening, performance improvements, and UI enhancements.
What's New
- Scanner IP Address Reference View and programmatically retrieve TruffleHog's scanner egress IP addresses — including static NAT IPs — from the dashboard and external API, simplifying firewall allowlisting for sources that restrict inbound connections.
- Availability: Enterprise Edition
- Asynchronous Source Deletion Deleting a large integration no longer blocks the UI or risks out-of-memory failures. Deletes return immediately with a "Deleting" state while cleanup runs in the background, and in-flight scan writes are guarded against sources mid-deletion.
- Availability: Enterprise Edition
- Jira Project Include/Exclude Configure which Jira projects to include or exclude directly in the source setup form, giving finer control over scan scope without editing raw configuration.
- Availability: Enterprise Edition
- Integration Management Improvements Filter deployed integrations by type, navigate shared secrets via full-row clicks, and benefit from predictable case-insensitive source search. A new source details page scaffold lays the groundwork for richer per-integration context.
- Availability: Enterprise Edition
- Slack OAuth Cancellation Feedback Users who cancel Slack authorization now see a clear warning toast instead of landing silently on an ambiguous page.
- Availability: Enterprise Edition
- Exclude Archived Repositories from GitHub Org Scans GitHub organization scans can now exclude archived repositories, reducing scope and noise for orgs with many inactive repos. Combining --repo with --include-repos/--exclude-repos now returns a clear error instead of silently ignoring filters.
- Availability: Open Source
- GitHub Action Registry Mirror Override The TruffleHog GitHub Action now accepts an image input to override the container image, enabling private registry mirrors for air-gapped and mirror-based CI environments.
- Availability: Open Source
Fixes
Bug fixes and correctness improvements across detection, response, administration, and infrastructure.
- Scanner Fleet Recovery The scanner fleet now recovers gracefully from post-update API overload, and scanners can start without an update payload, preventing stalls during rollouts.
- Availability: Enterprise Edition
- Summary Dashboard Attribution Fix The executive summary's "Top remediated integrations" now credits integrations based on current source attribution, fixing missing or double-counted entries for rotated secrets.
- Availability: Enterprise Edition
- Google Sheets Full-Workbook Export Google Sheets scanning now includes all sheets in a workbook rather than only the first, closing a gap where secrets in secondary tabs could be missed.
- Availability: Enterprise Edition
- Detector Accuracy Fixes Fixes across several detectors: Dropbox long-lived (sl.u.) tokens are no longer truncated before verification; Azure SAS tokens match regardless of parameter order; the Grafana detector correctly flags rotated secrets instead of treating them as valid; Confluence UUIDs no longer surface as false Atlassian secrets; the AWS detector produces deterministic output; Postgres honors ignore tags on default-port URLs; and the Klaviyo detector recognizes the newer key format.
- Availability: Enterprise and Open Source
- Accurate GitHub App Org Member Scanning GitHub App sources now enumerate organization members using per-installation tokens, fixing cross-org gaps in multi-org App deployments.
- Availability: Enterprise and Open Source
- Consistent Secret Redaction Redacted secret values in scan output now show the last four characters, matching the admin interface and making it easier to correlate CLI findings with the platform UI.
- Availability: Enterprise and Open Source
- Clearer S3 and CLI Diagnostics Explicitly configured S3 buckets now surface listing and role-assumption failures instead of suppressing them, and the scanner avoids terminal capability probes before writing CLI output (preventing garbled output in piped environments).
- Availability: Enterprise and Open Source