Portfolio concentration
91%
Top three share
Shows whether the organization is driven by one breakout repo or several visible projects.
Breadth
28 repos
Visible snapshot
5 repositories updated in the last 90 days.
Leading language
Unknown
Portfolio mix
Unknown (9), Go (9), Python (6)
Average size
27
Stars per repository
Useful for distinguishing one flagship-heavy publisher from a repeatable portfolio.
91%
of the visible star count comes from this organization's top three repositories.
27
stars per repository in this same snapshot.
Unknown
is the most common language here, with 5 repositories updated in the last 90 days.
Why this rank
This organization stands out because one flagship repo drives 66% of its visible star count.
Organization pages work best when you separate portfolio breadth from flagship concentration. In Truffle Security's case, the visible top three repositories account for about 91% of total stars in this snapshot, which helps explain whether the organization is known for one breakout project or for a broader repeatable portfolio.
The dominant language mix here is Unknown (9), Go (9), Python (6). That makes this page useful not just for popularity checks, but also for seeing what technical shape an organization's public ecosystem actually has.
| # | Repository | Language | Stars |
|---|---|---|---|
| 1 | trufflesecurity/force-push-scanner Scan for secrets in dangling commits on GitHub using GH Archive data. | Python | 490 |
| 2 | trufflesecurity/trufflehog-burp-suite-extension Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) using TruffleHog. | Python | 100 |
| 3 | trufflesecurity/how-to-rotate An open-source collection of API key rotation tutorials. | JavaScript | 86 |
| 4 | trufflesecurity/WhoAmISlack Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs. | Python | 41 |
| 5 | trufflesecurity/forager-scripts | Python | 7 |
| 6 | trufflesecurity/helm-charts | Mustache | 4 |
| 7 | trufflesecurity/test_keys | 3 | |
| 8 | trufflesecurity/hacktoberfest2023 Improve TruffleHog to win a laptop! | 3 | |
| 9 | trufflesecurity/pr-approval-check A Github Action that can be used to validate approvers. | 2 | |
| 10 | trufflesecurity/trufflehog-test-assets Test assets for trufflehog | 1 | |
| 11 | trufflesecurity/ldap-verify | Go | 1 |
| 12 | trufflesecurity/aho-corasick-bobusumisu Aho-Corasick string-searching algorithm in Go | Go | 1 |
| 13 | trufflesecurity/touchfile A reasonably simple locking mechanism between concurrent processes. | Go | 1 |
| 14 | trufflesecurity/waas-client-library-go Coinbase Wallet as a Service (WaaS) Client Library in Go. | Go | 1 |
| 15 | trufflesecurity/gosnowflake Go Snowflake Driver | Go | 1 |
| 16 | trufflesecurity/node-app-with-canary-token | JavaScript | 1 |
| 17 | trufflesecurity/go-bitbucket Fork of ktrysmt/go-bitbucket with updated Bitbucket Cloud API support. Intended to be temporary until upstream adopts these changes. | Go | 0 |
| 18 | trufflesecurity/leakyAPK | 0 | |
| 19 | trufflesecurity/common | 0 | |
| 20 | trufflesecurity/saml SAML library for go | 0 | |
| 21 | trufflesecurity/social-app-django Python Social Auth - Application - Django | Python | 0 |
| 22 | trufflesecurity/private-key-reuse-checker | Python | 0 |
| 23 | trufflesecurity/test_keys_internal Internal fork of test_keys used to test certain auth scenarios | 0 | |
| 24 | trufflesecurity/go-grpc-http1 A gRPC via HTTP/1 Enabling Library for Go | Go | 0 |
| 25 | trufflesecurity/aho-corasick efficient string matching in Golang via the aho-corasick algorithm. | Go | 0 |
| 26 | trufflesecurity/dependency-track Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. | 0 | |
| 27 | trufflesecurity/gosip ⚡️ SharePoint SDK for Go / Auth Strategy Updated for Oauth2.0 Flow | Go | 0 |
| 28 | trufflesecurity/terraform-gcp-logwarden Terraform module for running Logwarden in GCP | Open Policy Agent | 0 |
Total stars are useful as a discovery signal, but they do not tell you whether a team maintains every repository equally. Pair this page with release cadence, maintainer activity, and the flagship concentration shown above before making adoption decisions.
For broader background on GitStar's ranking logic and editorial guidance, see Methodology & Editorial Standards.