2026 February
3 min
find more secrets expand discovery across more areas of the environment and add detection for additional secret types, ensuring no secrets slip through the cracks what's new new detectors google gemini api key and openai admin key two new detectors expand credential coverage to google gemini api keys and openai admin keys, strengthening detection of ai service credentials that are increasingly common in modern environments availability enterprise edition and open source support for multi layer encoding with configurable depth decoders (base64, utf 16, escaped unicode) now chain iteratively each decoder's output is fed back through all decoders until no new transformations occur or max decode depth is reached (default 5) this finds secrets hidden inside layered encodings – for example, a base64 docker auth blob containing a gcp private key performance impact is less than 5% wall time availability enterprise edition and open source filesystem symlink following the filesystem source now supports following symbolic links with configurable maximum depth, enabling scanning of directory structures that use symlinks to reference sensitive files availability enterprise edition and open source tableau detector analysis support the tableau detector now includes analysis metadata, enabling richer context about the scope and permissions of detected tableau credentials availability enterprise edition and open source improved custom detector line numbers custom detector line number reporting now matches the full regex pattern instead of just the capture group, providing more accurate location information for remediation availability enterprise edition and open source support for buildkite artifact scanning via presigned s3 urls buildkite artifacts linked via presigned s3 urls can now be scanned availability enterprise edition improve response features here help teams act faster and more effectively when secrets are found, streamlining investigation, triage, and collaboration what's new scanner vs source error distinction when a source integration shows an error caused by its associated scanner, the ui now clearly distinguishes between scanner and source errors and provides a direct "view scanner" action for quick navigation to the scanner's detail page availability enterprise edition scan duration display improvements long running scan durations now display in human readable format using days and weeks (e g , "2w 3d" instead of "2000h"), making it easier to understand scan progress at a glance availability enterprise edition slack continuous reinstall flow slack continuous sources now support a reinstall/re authorization flow, allowing users to refresh credentials without recreating the entire source configuration availability available in enterprise edition lastverified timestamp fix fixed a bug where the lastverified timestamp reflected the time secrets were ingested into the platform rather than when verification actually occurred, which could cause secrets to appear verified after tokens had already expired availability available in enterprise edition
