Scanning Specific Branches with Trufflehog in Remote Repositories

So I am aware that you can specify a branch with TruffleHog when scanning git repositories after you've cloned them locally through the following:

trufflehog git --branch [branch-name] [your-repo-url]

However, say I'm working with GitHub Enterprise and trying to scan repositories remotely, without cloning every single one on the filesystem (for a bit more context, this is as part of a loop that goes through thousands of repos and performs this security scan).

I have already tried to something along the lines of the following commands:

  • trufflehog git --json --token [PAT] --endpoint [GHE_URL] --repo [GHE_URL/REPO] --branch master
  • trufflehog github --json --token [PAT] --endpoint [GHE_URL] --repo [GHE_URL/REPO] --branch master

in the hope it might just work despite knowing --branch isn't present in the help/man page for the github specifier, while git doesn't support --token.

Is there an actual way of doing this for just a specific branch (maybe a term/regex I might give it for name matching)? Perhaps a way to specify the branch name within the repository name in the --repo option?

To me this seems somewhat of a pretty basic functionality so it might just be me who's missing something. Thanks in advance!

Sarah Jenkins

Sarah Jenkins

Senior Technology Editor & AI Specialist

Sarah Jenkins is a veteran tech journalist with over 12 years of experience covering artificial intelligence, mobile innovations, and digital ethics. Her insights have appeared in leading technology publications worldwide.

Share this article