trufflesecurity/trufflehog

user (instead of org) with token is not working

Offen

#4.517 geöffnet am 26.10.2025

 (3 Kommentare) (1 Reaktion) (1 zugewiesene Person)Go (2.397 Forks)batch import
help wantedneeds-reconciliationpkg/sources

Repository-Metriken

Stars
 (26.285 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 28T 2h) (41 gemergte PRs in 30 T)

Beschreibung

TruffleHog Version

trufflehog 3.90.11

Expected Behavior

Considering this checks an user's repositories:

trufflehog github --org $user

And this checks an organization's repositories:

trufflehog github --org $org --token $GITHUB_TOKEN

This also should check an user's repositories, but now using a token:

trufflehog github --org $user --token $GITHUB_TOKEN

Actual Behavior

When a user is passed to --org and --token is specified, the repositories of the token's owner are being analyzed (instead of the specified user).

Steps to Reproduce

  1. Run the following command using a user instead of an organization:
trufflehog github --org $user --token $GITHUB_TOKEN
  1. Notice that the specified user' repositories will not be checked.

Potential Solution

I have a suggestion that worked here:

  1. Go to the function getReposByOrgOrUser inside pkg/sources/github/repo.go;
  2. Remove the parameter authenticated, and pass false to the function getReposByUser();
  3. Inside pkg/sources/github/github.go, update all the references that call getReposByOrgOrUser, removing the boolean parameter.

I did not create a PR because I feel this solution may have collateral effects that I cannot understand now, having a very superficial context of the code.

Contributor Guide