Skip to content

build(deps): bump trufflesecurity/trufflehog from 3.95.6 to 3.95.8#44

Merged
steipete merged 1 commit into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.95.8
Jul 6, 2026
Merged

build(deps): bump trufflesecurity/trufflehog from 3.95.6 to 3.95.8#44
steipete merged 1 commit into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.95.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor

Bumps trufflesecurity/trufflehog from 3.95.6 to 3.95.8.

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.95.8

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.95.7...v3.95.8

v3.95.7

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.95.6...v3.95.7

Commits
  • 00155c9 Include encoded resume info instead of clobbering it (#5110)
  • 4d3a66f fixed syntax error (#5109)
  • 797f02b [INS-334] Octopus Deploy detector (#4787)
  • 7f04a89 [INS-465] Skip unverified JWT Detector results when feature flag is enabled (...
  • 459d5a7 Add prometheus metrics for engine channels and workers (#5095)
  • f38f8f7 fix(azuresastoken): match SAS tokens regardless of parameter order (#5043)
  • 6261f5c removed "unauthorized" as exception for rotated graphana secrets (#5068)
  • f446421 [INS-407] Fixed AWS detector producing non deterministic output (#4836)
  • 885fa2d [INS-197] Add redhatpyxis api key detector (#4995)
  • c09d726 [INS-497] Add Pganalyze Read Key Detector (#4993)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.95.6 to 3.95.8.
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@30d5bb9...00155c9)

---
updated-dependencies:
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.95.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 3, 2026 07:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 3, 2026
@clawsweeper

clawsweeper Bot commented Jul 3, 2026

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed July 3, 2026, 3:36 AM ET / 07:36 UTC.

Summary
The branch updates .github/workflows/secret-scan.yml to use trufflesecurity/trufflehog v3.95.8 at commit 00155c9dc586f34d189adc83d3ac2698c2ec551f instead of v3.95.6.

Reproducibility: not applicable. this is a dependency bump rather than a bug report. The relevant source check is that current main still pins v3.95.6 and the PR updates that pin to v3.95.8.

Review metrics: 2 noteworthy metrics.

  • Workflow scope: 1 workflow changed, +1/-1. The diff is limited to the secret-scanning action pin and does not touch Go library code or public APIs.
  • Checks observed: 6 successful check runs. The updated workflow path, CI, and CodeQL all completed successfully on the PR head.

Merge readiness
Overall: 🐚 platinum hermit
Proof: 🌊 off-meta tidepool
Patch quality: 🐚 platinum hermit
Result: ready for maintainer review.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Rank-up moves:

  • none.

Next step before merge

  • No automated repair is needed; maintainers can handle this through the normal Dependabot dependency-update merge flow.

Security
Cleared: The diff changes a third-party GitHub Action execution path, but it remains pinned to the upstream v3.95.8 full SHA, keeps minimal workflow permissions, and adds no new secret or permission surface.

Review details

Best possible solution:

Merge the Dependabot bump after normal CI and maintainer dependency-review gates, keeping the action pinned to the upstream full commit SHA.

Do we have a high-confidence way to reproduce the issue?

Not applicable; this is a dependency bump rather than a bug report. The relevant source check is that current main still pins v3.95.6 and the PR updates that pin to v3.95.8.

Is this the best way to solve the issue?

Yes; updating the existing full-SHA action pin and matching version comment is the narrowest maintainable way to take this patch release.

AGENTS.md: found, but no applicable review policy affected this item.

Codex review notes: model internal, reasoning high; reviewed against 009c5f5894ae.

Label changes

Label justifications:

  • P3: This is a low-risk GitHub Actions dependency maintenance PR with no application runtime or exported API impact.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This is a Dependabot bot PR, so the external contributor real-behavior proof gate does not apply; successful CI and secret-scan runs are supplemental evidence.
Evidence reviewed

What I checked:

  • Repository policy read: Read the full target AGENTS.md; its crawlkit library boundary and validation guidance did not add a specific blocker for this GitHub Actions dependency bump. (AGENTS.md:1, 009c5f5894ae)
  • Current main pin: Current main still pins the secret-scan workflow to trufflesecurity/trufflehog@30d5bb91af1a771378349dbbb0c82129392acf70 # v3.95.6. (.github/workflows/secret-scan.yml:52, 009c5f5894ae)
  • PR diff scope: The PR changes only the TruffleHog action reference, replacing the v3.95.6 full SHA with the v3.95.8 full SHA. (.github/workflows/secret-scan.yml:52, 548d8b3cfd01)
  • Upstream tag verification: The upstream TruffleHog v3.95.8 tag resolves to 00155c9dc586f34d189adc83d3ac2698c2ec551f, matching the PR's pinned action SHA; v3.95.6 resolves to the current main pin. (00155c9dc586)
  • Checks and mergeability: GitHub reports the PR as mergeable/clean, with CI, CodeQL, and two secret-scan runs completed successfully against the PR head. (548d8b3cfd01)
  • Workflow provenance: git blame attributes the current secret-scan workflow and TruffleHog pin on main to the v0.13.2 release-prep commit, with earlier workflow hardening by Vincent Koc. (.github/workflows/secret-scan.yml:52, a8c08fa7ea68)

Likely related people:

  • steipete: GitHub commit metadata maps the current release-prep commit that last rewrote the secret-scan workflow on main to this handle. (role: recent area contributor; confidence: high; commits: a8c08fa7ea68; files: .github/workflows/secret-scan.yml)
  • vincentkoc: Git history shows this handle introduced the verified secret-scanning workflow and later pinned the GitHub Actions references to full commit SHAs. (role: introduced and hardened behavior; confidence: high; commits: ae16f4d2a0bd, 232aef3d30b8; files: .github/workflows/secret-scan.yml)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@clawsweeper clawsweeper Bot added rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. labels Jul 3, 2026
@steipete
steipete merged commit 3c1dc6d into main Jul 6, 2026
6 checks passed
@steipete
steipete deleted the dependabot/github_actions/trufflesecurity/trufflehog-3.95.8 branch July 6, 2026 07:42
@steipete

steipete commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Landed as 3c1dc6def34a010206cd6e9cce6ab86f2f9e433a.

Tested:

  • Local commands: none; this was a one-line GitHub Actions full-SHA pin update, so the meaningful runtime proof was the hosted workflow.
  • Live workflow proof on exact PR head 548d8b3cfd01dc4632d858bc83a35a3997bf5a58: Scan for Verified Secrets passed with TruffleHog v3.95.8; Linux test, Windows windows-test, and CodeQL analyze also passed.
  • Upstream pin verified: TruffleHog v3.95.8 resolves to 00155c9dc586f34d189adc83d3ac2698c2ec551f, matching the workflow.

Caveats: none.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant