All integrations

Tartufo Integration with DefectDojo

Tartufo Integration with DefectDojo

Tartufo is an open source secrets scanner maintained under GoDaddy's GitHub organization. It searches git repositories for credentials and other sensitive strings using regular expression rules and entropy analysis, and it examines the full commit history of each branch, not only the current working tree. It can scan a local clone, clone and scan a remote repository, check staged changes as a pre-commit hook, or scan a plain folder. With --output-format json it writes a JSON report that DefectDojo imports.

Tartufo Integration with DefectDojo

We use Tartufo because it looks where most leaks actually live: in old commits that nobody reads anymore. DefectDojo is where those hits get handled. Each Tartufo issue becomes a High Finding on the repository's Asset, carrying the commit hash, branch, and commit message that introduced the string, plus remediation text that says plainly the credential has to be rotated. Because DefectDojo tracks each finding by Tartufo's own signature, a nightly rescan of the same repository updates the existing findings instead of piling up new ones.

Why Tartufo Matters

Deleting a secret from the latest commit does not remove it from the repository. Anyone with a clone still has the history, and so does every fork and mirror.

  • Tartufo scans every commit on every branch, which catches secrets that were committed and later "removed".
  • It combines regex rules for known credential formats with entropy checks for random-looking strings that match no known pattern.
  • Each result names the file, branch, commit, and commit time, which is what an engineer needs to work out who must rotate what.
  • Tartufo gives each match a stable signature, which it also uses for its own exclusion lists, so known false positives can be suppressed precisely.

Advantages of This Integration

  • Stable tracking across rescans. DefectDojo deduplicates Tartufo findings on the Unique ID from tool field, which holds Tartufo's signature. The same secret in the same place matches the same Finding on every scan.
  • A severity that reflects exposure. Tartufo assigns no severity, so DefectDojo imports every hit as High. A secret in history should be treated as compromised, and High puts it under an SLA that makes someone rotate it.
  • Clear remediation text. Every Finding carries the same instruction: rotate the credential, because rewriting history does not undo the exposure.
  • Context without the secret. The parser records what was detected, the match type, the file, the branch, and the commit, but does not copy the matched string into DefectDojo.
  • Lifecycle with reimport. Reimporting into the same Test mitigates findings that no longer appear (for example after a history rewrite plus an exclusion), adds new ones, and reactivates any that return.
  • Shared triage. Findings can be assigned to the repository owner, pushed to Jira, risk accepted, or marked false positive like any other DefectDojo finding.

How This Integration Works

DefectDojo imports Tartufo output with the Tartufo Scan scan type.

1. Produce a JSON report. Run Tartufo against a local clone with JSON output:

tartufo --output-format json scan-local-repo . > tartufo.json

The parser reads the found_issues array from this report.

2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Tartufo Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Tartufo Scan" 
  -F "file=@tartufo.json" 
  -F "product_name=payments-api" 
  -F "engagement_name=Secrets" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Tartufo Scan" 
  --report-path "./tartufo.json" 
  --product-name "payments-api" 
  --engagement-name "Secrets" 
  --auto-create-context

3. Reimport on a schedule. Send later reports for the same repository to /api/v2/reimport-scan/ against the same Test, so findings keep their history and resolved ones are mitigated.

Data Granularity: What Gets Imported

DefectDojo Field Source in Tartufo Report Notes
Title issue_detail (or issue_type) and file_path For example AWS API Key in config.py
Severity Fixed Always High
Description Issue fields Detected rule, match type, file, branch, commit hash, commit message, commit time
File Path file_path File where the match was found
Unique ID from tool signature Tartufo's stable hash of the match
Vulnerability ID from tool issue_type For example Regular Expression Match or High Entropy
Mitigation Fixed text Rotate the exposed credential; removing it from history does not undo exposure
Matched string Not imported The secret value is not copied into DefectDojo
Line Not set Tartufo reports file and commit, not line
Finding type Static All findings are static
Deduplication Unique ID from tool Tartufo signature

Use Cases

Before open sourcing a repository: Run Tartufo across the full history and import the results. Every High Finding is a credential that must be rotated before the repository goes public, and DefectDojo tracks each one to closure.

Nightly history scans: A security team scans every repository nightly and reimports into one Test per repository. New Findings point at commits made since the last run, and the commit hash and branch tell the team which change introduced them.

After an incident: When a token leaks, search DefectDojo for Tartufo findings on the affected Assets. The commit time and branch help establish how long the credential was exposed and where.

Measuring cleanup: Because each finding stays open until rotation is recorded, security leads can report how many historic secrets remain per team and how long they have been open against SLA.

Operational Tips

  • Close a Tartufo finding only after the credential is rotated. Rewriting history alone leaves the old value valid for anyone who already cloned it.
  • When a hit is a known false positive, mark it false positive in DefectDojo and add its signature to Tartufo's exclusions so it stops appearing in future reports.
  • Expect the same secret to appear more than once if it was committed on several branches or in several files. Each location is a separate Finding to verify.
  • Keep the report file out of build artifacts that many people can read. The parser does not import matched strings, but the raw JSON may contain them.
  • Tag imports with the repository name so findings across a monorepo split are easy to filter.
  • Use the commit hash in the description to find the author and the date range of exposure when deciding how urgently to rotate.