Repository navigation
build(deps): bump trufflesecurity/trufflehog from 3.97.8 to 3.97.9 - #271
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.97.8 to 3.97.9. - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@a5f3de5...4dd8831) --- updated-dependencies: - dependency-name: trufflesecurity/trufflehog dependency-version: 3.97.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 6, 2026, 6:29 PM ET / 22:29 UTC (Revision 4). ClawSweeper reviewWhat this changesUpdates Discrawl’s secret-scanning GitHub Action pin from TruffleHog v3.97.8 to v3.97.9. Merge readiness✅ Ready for maintainer review The update remains useful: current main and v0.15.6 retain the older action pin. The published tag matches the proposed SHA, and no introduced correctness or security defect was found. Priority: P3 Review scores
Verification
How this fits togetherDiscrawl’s secret-scanning workflow receives push and pull-request commit ranges and checks them for verified credentials. Its result feeds the repository’s security checks before merging. flowchart TD
A[Push or pull request] --> B[Checkout repository history]
B --> C[Resolve commit range]
C --> D[TruffleHog action]
D --> E{Verified secrets found}
E -->|Yes| F[Fail security check]
E -->|No| G[Pass security check]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep the verified SHA-pinned action update while preserving the existing scan contract and restricted permissions. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates a dependency reference rather than reporting a reproducible product defect. Is this the best way to solve the issue? Yes: changing the existing SHA pin is a focused maintenance path, and the published tag and unchanged action contract support it. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 76618b71c379. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (3 earlier review cycles) |
|
Incorporated into #272, now merged. CodeQL initialization and analysis were updated together to v4.38.2 so their configuration versions match; the same PR includes TruffleHog v3.97.9 and groups future CodeQL updates. The combined head passed CodeQL, secret scans, full CI, and the remote Closing this separate update as superseded by the verified combined change. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps trufflesecurity/trufflehog from 3.97.8 to 3.97.9.
Release notes
Sourced from trufflesecurity/trufflehog's releases.
Commits
4dd8831Spruce up Makefile a little (#5347)449d8a3Int 595 auth errors (#5259)bad9901Add version and comment_number lines to SharePoint source metadata (#5348)4b8eb0emake 401s for Basic auth verified false. (#5290)bbf9447Update module github.com/gabriel-vasile/mimetype to v1.4.15 (#5283)16b566bUpdate module github.com/aymanbagabas/go-osc52 to v1.2.2 (#5252)a25ff85ci: scope Smoke timeouts to trufflehog runs, not the build (#5317)ca9d3b3[SCAN-162] Add Err() to JobProgress and JobProgressRef (#5346)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)