Skip to content

Commit f8a6445

Browse files
chore(deps): bump trufflesecurity/trufflehog from 3.93.4 to 3.93.7 (#31)
Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.93.4 to 3.93.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/trufflesecurity/trufflehog/releases">trufflesecurity/trufflehog's releases</a>.</em></p> <blockquote> <h2>v3.93.7</h2> <h2>What's Changed</h2> <ul> <li>[INS-331] Fix the issue causing the tests file system soruce tests to fail on windows by <a href="https://github.com/MuneebUllahKhan222"><code>@​MuneebUllahKhan222</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4743">trufflesecurity/trufflehog#4743</a></li> <li>Thread original chunk data through engine pipeline by <a href="https://github.com/dustin-decker"><code>@​dustin-decker</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4780">trufflesecurity/trufflehog#4780</a></li> <li>Added detector for JFrog Artifactory Reference Tokens by <a href="https://github.com/shahzadhaider1"><code>@​shahzadhaider1</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4684">trufflesecurity/trufflehog#4684</a></li> <li>Fix JDBC detector regex truncating trailing non-alphanumeric password characters by <a href="https://github.com/amanfcp"><code>@​amanfcp</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4755">trufflesecurity/trufflehog#4755</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/trufflesecurity/trufflehog/compare/v3.93.6...v3.93.7">https://github.com/trufflesecurity/trufflehog/compare/v3.93.6...v3.93.7</a></p> <h2>v3.93.6</h2> <h2>What's Changed</h2> <ul> <li>GH_TOKEN needed for gh by <a href="https://github.com/bill-rich"><code>@​bill-rich</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4772">trufflesecurity/trufflehog#4772</a></li> <li>Move verify flag into <code>detectableChunk</code> by <a href="https://github.com/rosecodym"><code>@​rosecodym</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4558">trufflesecurity/trufflehog#4558</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/trufflesecurity/trufflehog/compare/v3.93.5...v3.93.6">https://github.com/trufflesecurity/trufflehog/compare/v3.93.5...v3.93.6</a></p> <h2>v3.93.5</h2> <h2>What's Changed</h2> <ul> <li>Add workspace_id to Slack Continuous metadata by <a href="https://github.com/mariduv"><code>@​mariduv</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4749">trufflesecurity/trufflehog#4749</a></li> <li>fix(release): Disable docker provenance feature by <a href="https://github.com/mariduv"><code>@​mariduv</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4752">trufflesecurity/trufflehog#4752</a></li> <li>Base64 decoding depth assessment by <a href="https://github.com/dxa4481"><code>@​dxa4481</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4744">trufflesecurity/trufflehog#4744</a></li> <li>[INS-246] Add Google Gemini API key detector by <a href="https://github.com/mustansir14"><code>@​mustansir14</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4649">trufflesecurity/trufflehog#4649</a></li> <li>Refactor log package by <a href="https://github.com/mcastorina"><code>@​mcastorina</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4734">trufflesecurity/trufflehog#4734</a></li> <li>[INS-309]updated google api version to v0.259.0 by <a href="https://github.com/MuneebUllahKhan222"><code>@​MuneebUllahKhan222</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4736">trufflesecurity/trufflehog#4736</a></li> <li>fix(ftp): set read deadline on connection to prevent indefinite hang by <a href="https://github.com/dylanTruffle"><code>@​dylanTruffle</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4759">trufflesecurity/trufflehog#4759</a></li> <li>added rotation on 403s access_refused, this detector considered them indeterminate failures by <a href="https://github.com/jordanTunstill"><code>@​jordanTunstill</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4740">trufflesecurity/trufflehog#4740</a></li> <li>[INS-283] Support following symlinks in filesystem source by <a href="https://github.com/MuneebUllahKhan222"><code>@​MuneebUllahKhan222</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4742">trufflesecurity/trufflehog#4742</a></li> <li>Fix typos in comments in json-enumerator source by <a href="https://github.com/bradlarsen"><code>@​bradlarsen</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4764">trufflesecurity/trufflehog#4764</a></li> <li>Fix race condition in release process by <a href="https://github.com/bill-rich"><code>@​bill-rich</code></a> in <a href="https://redirect.github.com/trufflesecurity/trufflehog/pull/4766">trufflesecurity/trufflehog#4766</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/trufflesecurity/trufflehog/compare/v3.93.4...v3.93.5">https://github.com/trufflesecurity/trufflehog/compare/v3.93.4...v3.93.5</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/c3e599b7163e8198a55467f3133db0e7b2a492cb"><code>c3e599b</code></a> fix JDBC detector regex truncating trailing non-alphanumeric password charact...</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/71c48afda84ff44a58a04bf76e0520398ac21778"><code>71c48af</code></a> Added detector for JFrog Artifactory Reference Tokens (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4684">#4684</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/648aca62d5437454d477426fb20c29f402c06a4e"><code>648aca6</code></a> Thread original chunk data through engine pipeline (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4780">#4780</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/8df943f8298b6d3e45e6f01cc8f404efff8c109d"><code>8df943f</code></a> [INS-331] Fix the issue causing the tests file system soruce tests to fail on...</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/041f07e9df901a1038a528e5525b0226d04dd5ea"><code>041f07e</code></a> Move verify flag into <code>detectableChunk</code> (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4558">#4558</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/e9766030579a154b66f27fcaf0ca92e5a61426cf"><code>e976603</code></a> GH_TOKEN needed for gh (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4772">#4772</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/7cdc7ef878439f74842c00422c65ab864ed83125"><code>7cdc7ef</code></a> Fix race condition in release process (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4766">#4766</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/4f1d07f7c3bbc209ce0608d6b611e8a6031cc778"><code>4f1d07f</code></a> Fix typos in comments in json-enumerator source (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4764">#4764</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/4563dde124c011b7ab615dbe531b45f3a6193b96"><code>4563dde</code></a> [INS-283] Support following symlinks in filesystem source (<a href="https://redirect.github.com/trufflesecurity/trufflehog/issues/4742">#4742</a>)</li> <li><a href="https://github.com/trufflesecurity/trufflehog/commit/be889fa341b7a3b1c8d5fbd9e5c6ab378f417da8"><code>be889fa</code></a> added rotation on 403s access_refused, this detector considered them indeterm...</li> <li>Additional commits viewable in <a href="https://github.com/trufflesecurity/trufflehog/compare/7c0734f987ad0bb30ee8da210773b800ee2016d3...c3e599b7163e8198a55467f3133db0e7b2a492cb">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=trufflesecurity/trufflehog&package-manager=github_actions&previous-version=3.93.4&new-version=3.93.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
1 parent 13dd09e commit f8a6445

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/quality.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
find . -type f -perm /111 -name "*.sh" | head -10 || true
1919
2020
- name: Check for secrets
21-
uses: trufflesecurity/trufflehog@7c0734f987ad0bb30ee8da210773b800ee2016d3 # v3.93.4
21+
uses: trufflesecurity/trufflehog@c3e599b7163e8198a55467f3133db0e7b2a492cb # v3.93.7
2222
with:
2323
path: ./
2424
base: ${{ github.event.pull_request.base.sha || github.event.before }}

.github/workflows/secret-scanner.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
fetch-depth: 0 # Full history for scanning
1919

2020
- name: TruffleHog Secret Scan
21-
uses: trufflesecurity/trufflehog@7c0734f987ad0bb30ee8da210773b800ee2016d3 # v3
21+
uses: trufflesecurity/trufflehog@c3e599b7163e8198a55467f3133db0e7b2a492cb # v3
2222
with:
2323
extra_args: --only-verified --fail
2424

0 commit comments

Comments
 (0)