Ross ROSS = Recommend OSS · open-source software intelligence for agents

trufflesecurity/trufflehog

Find, verify, and analyze leaked credentials observed · 2026-08-28

github.com/trufflesecurity/trufflehog · homepage · Go · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 4.0
  • age_days: 3532
  • days_rel: 9
  • days_push: 7
  • n_releases_24m: 119

Full methodology

Adoption not part of the score

27599 stars · 2551 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

TruffleHog is an open-source secrets scanning tool that discovers, classifies, validates, and analyzes leaked credentials across Git repositories, object stores, filesystems, chats, and other sources. It detects over 800 credential types and verifies whether found secrets are live by attempting authentication with the providers.

Use cases

  • scan a git repository for leaked api keys and passwords
  • verify whether detected credentials are still active
  • block secrets from being committed with pre-commit hooks
  • scan docker images and s3 buckets for exposed secrets
  • find leaked aws keys in github history
  • run secret scanning in ci pipelines
  • analyze permissions of leaked cloud credentials

When to choose

  • you need to detect and verify leaked credentials in code, history, or cloud storage
  • you want secret scanning integrated into pre-commit hooks or CI/CD pipelines
  • you need broad coverage of 800+ credential types with live validation to cut false positives

When to avoid

  • you need continuous monitoring with dashboards, alerting, and SSO, which requires the enterprise product
  • you need a general-purpose static analysis or SAST tool rather than credential detection
  • your project cannot use AGPL-3.0 licensed software

Facets

cli-tool · maturity active

security vulnerability-scanning secrets-management developer-tools ci-cd security developer-tools version-control windows cli cross-platform secret-scanning credential-detection devsecops pre-commit git-scanning secret-verification devops linux macos docker

7 sources

Member repositories

RepositoryRoleHealth v2
trufflesecurity/trufflehogmain95

For agents

markdown · JSON · MCP: product_card(name="trufflesecurity/trufflehog")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem