Jenkins
6 min
Jenkins
Edition: Enterprise + Open Source
The Jenkins integration scans Jenkins build logs for credentials and other sensitive data.
Configuration
The Jenkins integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need:
- The URL of your Jenkins server.
- Credentials for a scanner account (basic auth) — or no credentials, if your Jenkins instance allows unauthenticated access to build logs.
Local configuration
Local configuration supports two authentication modes:
- Basic auth — uses a Jenkins account username and password.
- Unauthenticated — for Jenkins instances that allow anonymous read access to build logs.
Basic auth
sources:
- connection:
"@type": type.googleapis.com/sources.Jenkins
endpoint: https://jenkins.example.com
basicAuth:
username: scanner-account
password: XXXXXXXXXXXXXXXXXXXXXXXXXX
name: Jenkins logs
scanPeriod: 12h
type: SOURCE_TYPE_JENKINS
verify: true
Unauthenticated
sources:
- connection:
"@type": type.googleapis.com/sources.Jenkins
endpoint: https://jenkins.example.com
unauthenticated: {}
name: Jenkins logs
scanPeriod: 12h
type: SOURCE_TYPE_JENKINS
verify: true
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | Yes | The URI of the Jenkins server. |
insecureSkipVerifyTls | boolean | No | Skip TLS verification on the Jenkins server. Setting this to true may pose security issues. |
Capabilities
Feature | Supported |
|---|---|
Scan build logs | ✅ |
Scan base64-encoded data | ✅ |
Auto-resume | ✅ |
Notes
- The Jenkins integration scans build logs only. Job artifacts are not scanned.