Git
Git
Edition: Enterprise + Open Source
The Git integration scans Git repositories and local directories for credentials and other sensitive data.
Dependencies (Self-Hosted Deployment Only)
This setup requires specific tools for effective operation. Git is essential for repository management, while rpm2cpio, binutils, and cpio are necessary for extracting files from .rpm and .deb package formats.
- Git: For cloning repositories.
- rpm2cpio: To extract content from RPM packages.
- binutils: Includes the "ar" tool, crucial for extracting contents from .deb files.
- cpio: A versatile file archiver utility, compatible with various archive formats including .rpm and .deb.
Installing Dependencies on Ubuntu
To install these dependencies on an Ubuntu system, follow these steps:
- Open a terminal.
- Update your package lists to ensure you get the latest version available:
$ sudo apt update- Install the required packages:
sudo apt install git rpm2cpio binutils cpio
Configuration
The Git integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need credentials appropriate to the repositories you want to scan — see the local configuration section below for the supported authentication methods.
Local configuration
Local configuration supports three authentication methods:
- Basic authentication — uses a username and password (or token) for HTTPS clone access.
- SSH authentication — uses SSH keys from your local keychain.
- Unauthenticated — for public repositories or local directories that don't require authentication.
Basic authentication
Use this for HTTPS repositories that require username and password (or token) authentication.
SSH authentication
Use this for repositories accessed via SSH. SSH authentication uses keys from your local keychain.
Unauthenticated
Use this for public repositories or for scanning local directories that already contain Git clones.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
repositories | list | No | List of remote repositories to clone and scan. |
directories | list | No | List of local directories containing existing Git clones to scan. |
head | string | No | Branch or commit to use as the head of the scan range. |
base | string | No | Branch or commit to use as the base of the scan range. |
bare | boolean | No | Set to true if the repository is bare. |
maxDepth | integer | No | Maximum commit depth to scan. |
includePathsFile | string | No | Path to a file containing newline-separated paths to include in the scan. |
excludePathsFile | string | No | Path to a file containing newline-separated paths to exclude from the scan. |
excludeGlobs | string | No | Comma-separated list of glob patterns to exclude from the scan. |
skipBinaries | boolean | No | Skip binary files. |
skipArchives | boolean | No | Skip archive files. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan history | ✅ |
Include / exclude filters | ✅ |
Pre-commit | ✅ |
Pre-receive | ✅ |
Notes
- TruffleHog does not scan diffs larger than 1 GB.
Troubleshooting
Error | Cause | Solution |
|---|---|---|
cannot process 'refs/remotes/origin/...' and 'refs/remotes/origin/...' at the same time | Repository contains refs that conflict on disk during clone (e.g., a branch and a tag with overlapping paths). | Uncommon, but the scan will skip the affected repo and continue. If you need to scan a repo that consistently throws this error, open a bug report for workaround guidance. |