2026 March
Find More Secrets
Expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks.
What's New
- Additional Coverage with HTML Decoder
Sources like Atlassian Confluence and Microsoft Teams return scan-result content in HTML, which means secrets can be split across tags, embedded in attributes, or obscured by invisible characters. Weβre adding an HTML decoder to convert raw HTML into text before scanning so we can detect secrets we previously couldnβt. This new coverage may increase the number of discovered secrets.
- Availability: Enterprise Edition
- JFrog Artifactory Reference Token Detector New detector for JFrog Artifactory reference tokens, expanding coverage of Artifactory credential types beyond the existing access token detector.
- Availability: Enterprise Edition and Open Source
- Anypoint (MuleSoft) OAuth2 Analyzer New analyzer for Anypoint OAuth2 credentials providing comprehensive scope analysis covering 50+ API scopes across organizations, environments, applications, APIs, identity providers, design center, runtime fabrics, and more. Reports both verified and unverified scopes with connected app enumeration.
- Availability: Enterprise Edition
- SharePoint Source Enhancements Β SharePoint integration source enhancements for pagination, document handling, state tracking, and scan progress reporting.
- Availability: Enterprise Edition
- Jira Cloud/On-Prem Detection Override Jira sources now support explicit installation type configuration, allowing administrators to override the autodetection logic when it misidentifies the Jira deployment type.
- Availability: Enterprise Edition
- Confluence Space Attribution Fix Fixed an issue where secrets detected in Confluence were being attributed to the wrong spaces. Also fixed premature pagination termination that could cause incomplete scans.
- Availability: Enterprise Edition
- Improved Datadog API Key Detector Improved detector for Datadog API keys with multi-domain verification, endpoint configuration, and app key validation fallback. When app key verification fails, the detector falls back to API key-only verification and reports the verified endpoint in extra data.
- Availability: Open Source
- Datadog Detector Verification Fix The existing Datadog token detector now supports verification against all Datadog regional endpoints with configurable precedence (user-defined β discovered β default), fixing false negatives for customers using non-US Datadog regions.
- Availability: Open Source
- Forager: Expanded Diff Scanning Deleted files are now scanned in diff processing (previously silently skipped). A single failed commit no longer aborts processing of all remaining commits in a push event. Verification overlap is enabled for improved multi-detector success rates. TruffleHog updated to v3.93.8.
- Availability: Enterprise Edition
Improve Response
Features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration.
What's New
- Email Notifications Issues now auto-expand when accessed from email deep-links, improving the click-to-context experience. Email notification UX has been improved, and enabling issue alerts for the first time no longer triggers a flood of backlog notifications. Notifications for gateway-created issues that were previously silently dropped have also been fixed.
- Availability: Enterprise Edition
- GCP Analyze: Enhanced Table View and Role Analysis GCP Analyze now features a dedicated table view with role data expansion, role type filtering, and a key rotation drawer. Analysis metadata search enables finding secrets by their analyzed permissions and scope. Table/graph view state is preserved across navigation, and loading skeletons improve perceived performance.
- Availability: Enterprise Edition
- CSV Export: Date Rotated Field Secret exports now include a "Date Rotated" column, and all export timestamps have been standardized to a human-readable format for consistency across CSV consumers.
- Availability: Enterprise Edition
Ease Administration
Features here simplify ongoing management of the TruffleHog platform, including security hardening, performance improvements, and UI enhancements.
What's New
- K8s Gateway Support Kubernetes Gateway API is now supported for ingress routing, providing a modern alternative to Ingress resources for traffic management.
- Availability: Enterprise Edition
- Scanner Container Memory Awareness Scanners now detect cgroup memory limits for container-constrained environments, falling back to OS-level memory limits only when cgroup constraints are undefined. This prevents OOM kills in environments where container memory limits differ from host memory.
- Availability: Enterprise Edition
- LDAP Verification Context-Awareness LDAP verification now respects context cancellation, preventing the scan pipeline from stalling on unresponsive LDAP servers.
- Availability: Enterprise Edition and Open Source
- JDBC Detector Password Fix Fixed a regex issue that truncated trailing non-alphanumeric characters from JDBC connection string passwords, improving detection accuracy for passwords containing special characters.
- Availability: Enterprise Edition and Open Source
- Filesystem Scan Resume Fix Fixed a bug where filesystem scan resume data grew unboundedly across scan restarts, improving memory usage during large filesystem scans.
- Availability: Enterprise Edition and Open Source
- SharePoint Refresh Token Fix Fixed unauthenticated SharePoint OAuth refresh token updates that caused recurring scan failures when tokens expired.
- Availability: Enterprise Edition
- HTTP/2 Proxy Environment Fix HTTP/2 connections correctly pick up proxy settings from environment variables.
- Availability: Enterprise Edition
- Environment Variable Expansion Fix Scanner configuration environment variables are now only expanded when set, preventing empty-value substitution that could silently misconfigure scans.
- Availability: Enterprise Edition
Security
- Django 5.2 LTS Migration Migrated to Django 5.2 LTS and upgraded social-auth-app-django, ensuring long-term security support and addressing known vulnerabilities.
- Availability: Enterprise Edition
- Dependency Security Updates Remediated vulnerable dependencies including gRPC v1.79.3 security update and tar package security fixes. Additional actionable dependency vulnerabilities patched.
- Availability: Enterprise Edition
- TUI Command Injection Fix Fixed a command injection vulnerability in the TUI where shell metacharacters in input fields (git URI, file path, tokens) could be interpreted as shell commands. The TUI now executes trufflehog directly without shell interpretation and adds a narrow tilde expansion helper for path resolution.
- Availability: Open Source