CircleCI
5 min
CircleCI
Edition: Enterprise + Open Source
The CircleCI integration scans CircleCI build logs for credentials and other sensitive data. To scan the contents of your CI pipeline, see Scanning in CIScanning in CI instead.
Configuration
The CircleCI integration is configured via a local configuration file. Web configuration in TruffleHog is not available for this source.
Local configuration
sources:
- connection:
"@type": type.googleapis.com/sources.CircleCI
token: XXXXXXXXXXXXXXXXXXXXXXXXXX
name: CircleCI logs
scanPeriod: 12h
type: SOURCE_TYPE_CIRCLECI
verify: true
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes | A CircleCI API access token. |
Capabilities
Feature | Supported |
|---|---|
Scan build logs | ✅ |
Scan base64-encoded data | ✅ |
Auto-resume | ✅ |
Notes
- Build artifacts are not scanned. The CircleCI integration covers build logs only.
- Include and exclude filters are not supported. The scanner covers all build logs the token has access to.