Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

trufflehog package no longer maintained #15

Open
gabelton opened this issue Jan 24, 2024 · 2 comments
Open

trufflehog package no longer maintained #15

gabelton opened this issue Jan 24, 2024 · 2 comments

Comments

@gabelton
Copy link

Last version was released early Feb 2021 https://pypi.org/project/truffleHog/#history

The package depends on a version of gitpython containing a security vulnerability, which was flagged by s3proxy https://github.com/uktrade/s3proxy/security/dependabot/53

@gabelton
Copy link
Author

From the author of the package:

TruffleHog v2 is about 2 or 3 years past EOL. TruffleHog v3 is written in Go, and not presently distributed on PyPi. You can download the latest release here: https://github.com/trufflesecurity/trufflehog/releases/tag/v3.64.0

Or pull from our docker register https://hub.docker.com/r/trufflesecurity/trufflehog/tags

However please be aware the latest version is not 100% backwards compatible with V2, and it has a significant number of features that were added, most notably key verification (automatically trying to log in with the keys identified to confirm if they're still live).

Another big change is, this project is no longer a research project, it's not fully supported by a company that was founded in 2021, backed by A16Z and has enterprise features and support available.

@MattHolmes123
Copy link

MattHolmes123 commented Jan 26, 2024

Looks like TruffleHog v3 can just be run as a pre-commit hook anyway:
https://github.com/trufflesecurity/trufflehog#pre-commit-hook

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants