TruffleHog
An open secret scanner for Git repositories, filesystems, container images, CI systems, and cloud sources, with many detectors able to verify whether discovered credentials remain active.
Why it’s here
Pre-release scanning can stop API keys, store credentials, and backend secrets from entering patches or public repositories, while verification separates historical noise from exploitable findings.
Best fit
Testing, performance, accessibility, and diagnostics expose friction before launch.
Before you commit
Live verification sends network requests to relevant services, so sensitive or offline environments should disable it and review logs; AGPL-3.0 duties need review before redistribution or hosted modification.