TruffleHog
An open secret scanner for Git repositories, filesystems, container images, CI systems, and cloud sources, with many detectors able to verify whether discovered credentials remain active.
Why use it
Pre-release scanning can stop API keys, store credentials, and backend secrets from entering patches or public repositories, while verification separates historical noise from exploitable findings.
Where it fits
Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.
What to check
Live verification sends network requests to relevant services, so sensitive or offline environments should disable it and review logs; AGPL-3.0 duties need review before redistribution or hosted modification.