From 54b33dd563ef2354e157408c12f0156772db3e72 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 3 Mar 2025 13:22:05 +0000 Subject: [PATCH] Bump trufflesecurity/trufflehog from 3.88.12 to 3.88.14 Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.88.12 to 3.88.14. - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Changelog](https://github.com/trufflesecurity/trufflehog/blob/main/.goreleaser.yml) - [Commits](https://github.com/trufflesecurity/trufflehog/compare/a2a17cd73d74376209d6323c80a9a55b424e25b0...7dc056a193116ba8d82154bf0549381c8fb8545c) --- updated-dependencies: - dependency-name: trufflesecurity/trufflehog dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/scan-secrets.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/scan-secrets.yml b/.github/workflows/scan-secrets.yml index 917ecdc1..1824a90d 100644 --- a/.github/workflows/scan-secrets.yml +++ b/.github/workflows/scan-secrets.yml @@ -16,7 +16,7 @@ jobs: fetch-depth: 0 # Getting all refs for git mode - name: Secret Scanning # Okay for using the latest since specified the CLI version below. Consider to pin with a tag if the project looks unstable - uses: trufflesecurity/trufflehog@a2a17cd73d74376209d6323c80a9a55b424e25b0 # main + uses: trufflesecurity/trufflehog@7dc056a193116ba8d82154bf0549381c8fb8545c # main with: extra_args: --results=verified,unknown version: '3.88.13' # selfup {"extract":"\\d[^']+","replacer":["bash", "-c", "trufflehog --version 2>&1"],"nth":2}