2026 May
5 min
Find More Secrets
Expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks.
What's New
- Ignore Repos for Public GitHub Scanning When scanning a public GitHub organization, you can now exclude specific repositories from the scan. This reduces noise from repos you don't need to monitor, such as forks or archived projects.
- Availability: Enterprise Edition
- Google Drive Scanning Improvements Google Drive scans now handle large folder hierarchies more reliably. A new folder-based enumeration approach reduces memory pressure during scanning and resolves file paths more efficiently, preventing timeouts and incomplete scans for organizations with deeply nested Drive structures.
- Availability: Enterprise Edition
- AWS AppSync Detector New detector for AWS AppSync API keys. Identifies exposed AppSync credentials and verifies them against the AWS API to confirm whether they grant access to your GraphQL endpoints.
- Availability: Enterprise and Open Source
- GitLab OAuth Detector New detector for GitLab OAuth application credentials. Verifies tokens against the GitLab API and extracts application context for triage.
- Availability: Enterprise and Open Source
- SpectralOps Personal API Key Detector New detector for SpectralOps personal API keys, expanding coverage to this security tooling platform.
- Availability: Enterprise and Open Source
- Database Credential Context MongoDB, PostgreSQL, Redis, and JDBC findings now include host, database name, and username directly in the finding metadata. Responders can immediately see which system a credential accesses without manually parsing connection strings.
- Availability: Enterprise and Open Source
- APK Scanning Improvements Improved handling of obfuscated Android APK files and APKs with non-standard resource types.
- Availability: Enterprise and Open Source
- Duplicate Secret Line Number Fix Fixed incorrect line numbers reported when the same secret appeared multiple times within a single file chunk. Findings now point to the correct source line for each occurrence.
- Availability: Enterprise and Open Source
- Twilio Deduplication Fix Fixed a match explosion in the Twilio detector that could produce a large number of duplicate results, significantly reducing noise in Twilio-heavy environments.
- Availability: Enterprise and Open Source
- GitHub Repository Redirect Fix Scanning no longer re-fetches repository metadata for GitHub repos that have been renamed or transferred. Repo info is now cached under the original URL on redirect.
- Availability: Enterprise and Open Source
- ASPX and Entity-Encoded HTML Support The HTML decoder now handles ASPX pages and entity-encoded HTML content.
- Availability: Enterprise and Open Source
Improve Response
Features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration.
What's New
- Additional Triage States You can now classify findings with four additional Triage States, giving security teams finer-grained control over remediation workflows. The new states — In Review (actively investigating validity, ownership, and scope), Notified (responsible party informed, remediation pending), In Progress (rotation, revocation, or removal underway), and Exception (risk formally accepted with owner and review date tracking) — sit alongside the existing four to reflect each stage of the remediation lifecycle.
- Availability: Enterprise Edition
- Multi-Analyzer Credential Analysis Credential analysis now runs multiple analyzers per finding where applicable. For example, a Bitbucket credential is analyzed by both the Bitbucket and Atlassian analyzers, and a MySQL credential by both the MySQL and JDBC analyzers. This means richer context about what a credential can access, without any additional configuration.
- Availability: Enterprise Edition
- Analyze Tab as Default View When credential analysis data is available for a secret, the detail page now opens directly to the Analyze tab. This puts the most actionable information — what the credential can access and its risk profile — front and center, saving a click on every investigation.
- Availability: Enterprise Edition
- Secret Reverification You can now reverify stored secrets on demand, across any integrated source, to confirm whether a previously detected credential is still active, even if the original source (repo, Slack message, Confluence page, Jenkins log) has been deleted. Trigger reverification from the secret details page or programmatically via the new async POST/secret-reverification endpoint.
- Availability: Enterprise Edition (Private Preview)
Ease Administration
Features here simplify ongoing management of the TruffleHog platform, including security hardening, performance improvements, and UI enhancements.
What's New
- Configurable Liveness Probe Timeout (Helm) The trufflehog Helm chart (0.5.0) now lets you customize the liveness probe timeout, useful for deployments where scanner startup takes longer than the default threshold. Set it via the chart values to match your environment.
- Availability: Enterprise Edition
- Smarter Notification Creation Newly created notification sinks now only fire for secrets discovered after the sink was set up. Previously, a new notifier could trigger alerts for historical findings, creating unnecessary noise during onboarding.
- Availability: Enterprise Edition
- Faster Dashboard Loading The Summary dashboard now loads significantly faster by reading from an optimized data path. Large deployments with many secrets should see noticeably reduced page load times.
- Availability: Enterprise Edition
- Location Filter Fix Fixed an issue where filtering secrets by location name used substring matching instead of exact match. For example, selecting "acme" would also return secrets from "acme-foo." Filters now match exactly what you select.
- Availability: Enterprise Edition
- Jira Notifier Fix Resolved an issue where Jira notification sinks could fail with "unsupported notifier type" errors, preventing ticket creation for new findings. Jira and test notifier types are now fully supported in the notification pipeline.
- Availability: Enterprise Edition
- Email Notifier Fix Fixed an issue where email notifications configured via SES were not including recipients, causing notifications to silently fail to deliver.
- Availability: Enterprise Edition
- GitHub App Name Fix Fixed 404 errors that occurred when a GitHub App's name contained spaces, which prevented the integration from completing API calls.
- Availability: Enterprise Edition
Security
- Session and Cookie Hardening Strengthened session security by enforcing HTTPS-only cookies, setting HttpOnly and SameSite attributes on session cookies, and adding Cache-Control: no-store headers to all API responses to prevent sensitive data from being cached to disk.
- Availability: Enterprise Edition
- Dependency Vulnerability Patches Updated vulnerable frontend, backend, and Go dependencies across the platform.
- Availability: Enterprise Edition
Infrastructure & Reliability
- Secret Ingestion Throughput Fix Resolved a regression that throttled secret ingestion to a fraction of its intended capacity. Throughput is restored to normal levels, eliminating processing backlogs during large scans.
- Availability: Enterprise Edition
- Smarter Circuit Breaker The secret ingestion circuit breaker now distinguishes between normal scan spikes and sustained overload, reducing false-positive load shedding during healthy scan activity.
- Availability: Enterprise Edition
- Duplicate Task Prevention The platform now prevents the same scan task from being dispatched to multiple scanners simultaneously, eliminating redundant work caused by retry races.
- Availability: Enterprise Edition