Webhook
This feature is only available with TruffleHog Enterprise. Contact us to learn more.
Webhook notifiers allow for integrations which subscribe to found secret notifications.
When a new secret is found, an HTTP POST payload will be sent to the webhook’s configured URL. Webhooks can be secured by using a token to generate and verify a signature of the payload.
For platforms such as Sumo Logic that do not accept X-Hub-Signature headers natively, then you may need to provide a pre-signed URL instead. This allows you to authenticate without a token, and the token: parameter can be removed from your config.yml.
Scanner Configuration
notifiers:
- connection:
'@type': type.googleapis.com/notifiers.Webhook
token: secret_token
url: https://example.trufflesec.com:8081/webhook
notifyOnRotation: false
name: webhook secrets notifications
# sourcesToNotify can also be set to ALL to receive
# all notifications
sourcesToNotify: SOURCES_IN_THIS_CONFIG
type: NOTIFIER_TYPE_WEBHOOK
heartbeatInterval: interval_in_hoursOptions
Key | Description | Required |
|---|---|---|
url | The webhook endpoint to send the notification to | Yes |
token | Token to generate signature for webhook | No |
notifyOnRotation | Set to true to send follow-up webhook notification when secret is rotated | No |
signatureMethod | sha256 or hmac-sha256. Default: sha256 | No |
base64EncodedToken | Set to true if provided token is base64 encoded | No |
heartbeatInterval | One of: 0, 1, 2, 6, 12, 24. Set to 0 to disable heartbeats, set to any other value to enable heartbeats | No |
Tokens
The signature is sent using in the X-Hub-Signature header. To verify the signature matches the payload, generate a SHA256 hash of the payload body prefixed with the token string.
Example payload body by source
{
"SourceType": "SOURCE_TYPE_GITLAB",
"Metadata": {
"Data": {
"Gitlab": {
"file": "file-1",
"link": "https://gitlab.com/org/repo/blob/ae3e9d0f0516d52113386c1e75032536143a241c/file-1",
"repository": "repo-1",
"line": 42,
"timestamp": "2020-05-01T00:00:00Z",
"commit": "ae3e9d0f0516d52113386c1e75032536143a241c",
"email": "[email protected]"
}
}
},
"SecretType": "Github",
"Secret": "SOMESECRET",
"Verified": false
}