GitLab
GitLab
Edition: Enterprise + Open Source
The GitLab integration scans repositories in GitLab for credentials and other sensitive data. To scan artifacts produced by GitLab CI pipelines, see Scanning in CIScanning in CI instead.
Dependencies (Self-Hosted Deployment Only)
This setup requires specific tools for effective operation. Git is essential for repository management, while rpm2cpio, binutils, and cpio are necessary for extracting files from .rpm and .deb package formats.
- Git: For cloning repositories.
- rpm2cpio: To extract content from RPM packages.
- binutils: Includes the "ar" tool, crucial for extracting contents from .deb files.
- cpio: A versatile file archiver utility, compatible with various archive formats including .rpm and .deb.
Installing Dependencies on Ubuntu
To install these dependencies on an Ubuntu system, follow these steps:
- Open a terminal.
- Update your package lists to ensure you get the latest version available:
$ sudo apt update- Install the required packages:
sudo apt install git rpm2cpio binutils cpioConfiguration
The GitLab integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need either:
- A GitLab personal or project access token with the read_api scope, or
- Basic auth credentials for a service account.
Local configuration
Local configuration supports two authentication methods:
- Access token — uses a GitLab personal or project access token with the read_api scope.
- Basic auth — uses a service account username and password.
Access token
Basic auth
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | No | The URL endpoint for the GitLab server. Defaults to GitLab Cloud. |
repositories | list | No | Explicit list of repository names to scan. Omit to enumerate instead. |
includeRepos | list | No | Repositories to include in organization scans. Supports glob patterns (*). |
ignoreRepos | list | No | Repositories to skip during organization scans. Supports glob patterns (*). |
skipBinaries | boolean | No | Skip binary files. |
skipArchives | boolean | No | Skip archive files. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan archived repositories | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan GitLab Actions | ✅ |
Include / exclude filters | ✅ |
Pre-commit | ✅ |
Pre-receive | ✅ |
Auto-resume | ✅ |
Notes
- TruffleHog does not scan diffs larger than 1 GB.
- For artifacts produced by GitLab CI pipelines, use the GitLab CI source rather than this integration.
Troubleshooting
Error | Cause | Solution |
|---|---|---|
cannot process 'refs/remotes/origin/...' and 'refs/remotes/origin/...' at the same time | Repository contains refs that conflict on disk during clone (e.g., a branch and a tag with overlapping paths). | Uncommon, but the scan will skip the affected repo and continue. If you need to scan a repo that consistently throws this error, open a bug report for workaround guidance. |