Azure Repos (cloud)
Azure Repos (cloud)
Edition: Enterprise only
The Azure Repos integration scans repositories in Azure DevOps for credentials and other sensitive data.
Configuration
The Azure Repos integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need a personal access token (PAT) from Azure DevOps with the Code (read) scope.
Local configuration
Create a personal access token
- In Azure DevOps, click the User Settings icon in the top right next to your profile picture.
- Click Personal access tokens.
- Click New Token.
- Name the token, select an organization, and choose Custom defined. Then select the Code (read) scope.
- Click Create.
Configure scope
When specifying organizations, projects, and repositories, keep in mind:
- At least one organization is required.
- The hierarchy is organizations > projects > repositories. Projects must belong to specified organizations, and repositories must belong to specified projects.
- Specifying only organizations scans all their projects. Specifying only projects scans all their repositories.
- Ignore filters always override include filters, for both projects and repositories.
Access token
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
organizations | list | Yes | List of organizations to scan. At least one is required. |
endpoint | string | No | Endpoint URL for Azure Repos. |
projects | list | No | List of projects to scan. |
includeProjects | list | No | Projects to include in scanning. |
ignoreProjects | list | No | Projects to skip during scanning. |
repositories | list | No | Explicit list of repositories to scan. Omit to enumerate instead. |
includeRepos | list | No | Repositories to include in scanning. |
ignoreRepos | list | No | Repositories to skip during scanning. |
includeForks | boolean | No | Include forked repositories. |
skipBinaries | boolean | No | Skip binary files. |
skipArchives | boolean | No | Skip archive files. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan archived repositories | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
History | ✅ |
Include / exclude filters | ✅ |
Pre-commit | ✅ |
Auto-resume | ✅ |
Notes
- TruffleHog does not scan diffs larger than 1 GB.
- Only cloud-hosted Azure Repos are supported. Self-hosted Azure DevOps Server is not scannable.