Gerrit
Gerrit
Edition: Enterprise only
The Gerrit integration scans projects in Gerrit for credentials and other sensitive data.
Configuration
The Gerrit integration can be configured in TruffleHog under Integrations, or via a local configuration file (below). TruffleHog scans only the projects the configured credentials have access to.
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need credentials for a Gerrit account with read access to the projects you want to scan, or anonymous access if your Gerrit instance allows it.
Local configuration
Local configuration supports two authentication methods:
- Basic authentication — uses a Gerrit account username and password.
- Unauthenticated — for Gerrit instances that allow anonymous read access.
If projects is omitted, all projects the credential can list and access will be scanned.
Basic authentication
Unauthenticated
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | Yes | The URL endpoint for the Gerrit service. |
projects | list | No | Explicit list of projects to scan. Omit to enumerate instead. |
skipBinaries | boolean | No | Skip binary files. |
skipArchives | boolean | No | Skip archive files. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
History | ✅ |
Exclude filter | ✅ |
Auto-resume | ✅ |
Notes
- TruffleHog does not scan diffs larger than 1 GB.
Troubleshooting
Error | Cause | Solution |
|---|---|---|
cannot process 'refs/remotes/origin/...' and 'refs/remotes/origin/...' at the same time | Repository contains refs that conflict on disk during clone (e.g., a branch and a tag with overlapping paths). | Uncommon, but the scan will skip the affected repo and continue. If you need to scan a repo that consistently throws this error, open a bug report for workaround guidance. |