Jira
Jira
Edition: Enterprise only
The Jira integration scans issue descriptions, comments, and attachments in Atlassian Jira for credentials and other sensitive data. To send TruffleHog detections to Jira as notifications, see the Jira notifier instead.
Configuration
The Jira integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need credentials appropriate to your Jira deployment — see the local configuration section below for the supported authentication methods.
Local configuration
Local configuration supports three authentication modes, depending on your Jira deployment:
- Jira Cloud (basic auth) — uses your Atlassian email address as the username and a Jira Cloud API token as the password. Jira service accounts are not supported at this time.
- Jira Server / Data Center (bearer token) — uses a personal access token (PAT).
- Jira Server / Data Center (basic auth) — uses an account username and password.
If projects is omitted, all projects the credentials can list and access are scanned.
Jira Cloud (basic auth)
Use this for Jira Cloud. The username must be the email address attached to your Atlassian account, and the password must be a Jira Cloud API token. Standard passwords cannot be used in place of an API token for Jira Cloud.
Jira Server / Data Center (bearer token)
Use this for self-hosted Jira with a personal access token.
Jira Server / Data Center (basic auth)
Use this for self-hosted Jira with username and password authentication.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | Yes | The URL of the Jira instance. |
projects | list | No | Explicit list of project keys to scan. Omit to enumerate instead. |
ignoreProjects | list | No | Project keys to skip during scanning. Combines with enumeration. |
insecureSkipVerifyTls | boolean | No | Skip TLS certificate verification. Setting this to true may pose security issues. |
Capabilities
Feature | Supported |
|---|---|
Scan issue descriptions | ✅ |
Scan comments | ✅ |
Scan attachments | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Auto-resume | ✅ |