2025.9
Version | |
---|---|
2025.9.0 | September 17, 2025 |
System Requirements Update
Ensure your infrastructure meets the latest requirements for optimal performance and security:
Component | Minimum Version | Recommended Version |
---|---|---|
KOTS | 1.117.3 | Latest |
Kubernetes | 1.28 | 1.32 |
PostgreSQL | 15 | 16 |
Redis | 6 | 7 |
ggscout | 0.19.0 | Latest |
Helm & Upgrade Considerations
To ensure compatibility, please review Helm values updates from the previous version. Air gap deployment? Find all the images and tag names in the air gap install page.
Now, Bring Your Own Sources!
We're excited to announce the launch of Bring Your Own Sources, a powerful new feature that allows you to extend GitGuardian's secret detection capabilities to any data source, whether it's CI logs, legacy systems, local filesystems, or SFTP servers. This feature empowers you to seamlessly integrate custom sources into your existing security monitoring workflow.
Why You'll Love It:
- Infinite Flexibility: Scan any source, regardless of native integration support, and manage incidents directly in the GitGuardian dashboard.
- Comprehensive Coverage: Eliminate detection gaps and ensure comprehensive coverage across all your environments, especially those highly isolated.
- Seamless Integration: Integrate sources within minutes, incidents automatically appear in the GitGuardian interface.
How It Works:
- Declare a Custom Integration: Use the GitGuardian dashboard to create a custom source and receive a unique ID.
- Scan Your Data: Use ggshield, custom script or any automation tool to scan content from your custom sources.
- Manage Incidents: View and manage all findings in the GitGuardian dashboard with full filtering and incident management capabilities.
It's Future-Proof:
We're planning enhancements in the coming months, like multi-source support per integration and larger file limits.
We'd love to hear from you: Let us know how it solved your challenges or how we can improve to help you solve them!
Get Started Today!
- Look into our documentation to help you get started.
- Or dive into our Blog Post Series to start securing your custom sources with GitGuardian!
Introducing Quick Access, your shortcut to efficiency!
We're thrilled to unveil Quick access, a powerful new feature designed to streamline your navigation and boost productivity within the GitGuardian platform.
It offers a unified search interface that allows you to swiftly access different parts of the application, search documentation — all from one convenient location.
Why you'll love it:
Quick access is designed to make your experience with GitGuardian smoother and more efficient:
- Faster navigation: Reduce time spent navigating through complex menu structures.
- Context-aware results: Search results adapt based on your current location and permissions.
- Enhanced productivity: Spend less time searching and more time doing.
How to use:
- Access: Use Ctrl+K (or Cmd+K on Mac) to open it from anywhere in the platform.
- Search: Type your query to find pages, documentation.
- Navigate: Use arrow keys to browse results and press Enter to select.
Try it out today and let us know what you think! Check out our documentation to learn more!
Secrets Scanning now available for Microsoft SharePoint and OneDrive
In the era of agentic AI, safeguarding your organization's knowledge database is more crucial than ever.
We're excited to announce that GitGuardian now supports secrets scanning for Microsoft SharePoint and OneDrive, empowering you to protect sensitive information from inherent breaches and mitigate risks effectively.
What does this mean for you?
- Comprehensive Security: Automatically detect and remediate exposed secrets in your SharePoint and OneDrive files, ensuring your data remains secure.
- Proactive Protection: Identify and address potential vulnerabilities before they can be exploited or ingested by your LLM providers or internal AI agents.
- Seamless Integration: Easily incorporate this new scanning capability into your existing GitGuardian setup for a unified security approach.
Why is this important?
As AI continues to evolve, the potential for breaches increases. By securing your organization's knowledge base, you can prevent the ingestion of compromised secrets by LLMs or internal AI Agents, ultimately preventing your secrets from falling into the wrong hands. With GitGuardian's new scanning capabilities, you can confidently navigate the digital landscape, knowing your secrets are safe.
Secure your collaboration. Protect your business.
Simply connect your Microsoft Teams instance and let our enhanced detection engine do the rest. Our solution will automatically scan both ongoing and historical SharePoint Online and OneDrive content, surfacing any hardcoded secrets for prompt remediation.
Check out our documentation to get started now!
Introducing AI Filters - It's time to have a conversation with your data!
We're excited to introduce AI Filters - use natural language to filter data across Incidents, Perimeter, and Audit Logs. Finding what you need has never been easier.
What it does:
- Type queries in plain English (e.g., "Show me critical incidents from last week")
- AI automatically converts your request into the appropriate filters
- Works alongside your existing filter settings
- Save AI-generated filters as views for team sharing
Available in: Incidents, Perimeter, and Audit Logs
Look for the AI input field in your filter bars to get started! Learn more about AI filters.
Secrets Detection Engine (v2.146)
New Detectors
- Africa's Talking API Key – Africa's Talking provides SMS, voice, and payment APIs for businesses in Africa.
- Clipdrop API Key – Clipdrop offers AI-powered image editing and enhancement tools.
- StackHawk API Key – StackHawk enables automated application security testing for developers.
- Murf API Key – Murf provides AI voice generation and text-to-speech services.
Detector Improvements
- Stripe Keys – Updated Stripe checker to prevent timeouts during checks.
- GitLab Token – Detector Upgrade: Broader regex for
gitlab_personal_token_v2
to match longer tokens, enhancing detection capabilities for GitLab personal tokens.
Enhancements
- Confluence Cloud Integration: Enhanced Confluence Cloud secret scanning to work with outbound-only network connections through OAuth2 authentication, eliminating the need for inbound access previously required by Connect app installations. This improvement enables organizations with strict network policies to securely scan their Confluence Cloud content using historical scanning capabilities. Learn more
- User management: Managers can allow users with the "Can view" incident permission to comment and provide feedback, improving collaboration without granting edit rights. Learn more
- GitHub Check Runs: Added option to include public share links in check runs, enabling developers outside your workspace to access and resolve incident details directly from pull requests without requiring GitGuardian dashboard access. Learn more
- Security: Added Content Security Policy (CSP) headers to improve browser security.
Fixes
- Token Management: Removed the unnecessary service account token link from the personal access token page for members.
- Remediation tracking: Disabled file tracking for non-default branches. Learn more
- Perimeter: Fixed "invalid time value" error when applying filters with running bulk scans.
- Notifications:
- Fixed Honeytoken events to only appear in "All incidents" team notifications instead of all teams.
- Fixed custom webhook URL validation to properly handle escaped URLs.
- Integrations:
- Fixed installation validation blocking customers from setting up on-prem JFrog Docker registry integration.
- Fixed direct URL display in occurrences for older Confluence Data Center versions.
- Self-Hosted:
- Fixed Loki image not being pulled from private Docker registry during airgap Helm installations.
- Resolved KOTS rendering issue on existing cluster with KOTS installation. Note: KOTS installation will be deprecated soon. We encourage customers to migrate to Helm installation.