build(deps): bump trufflesecurity/trufflehog from 3.97.5 to 3.97.9 - #259
Conversation
Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.97.5 to 3.97.9. - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@f714bf4...4dd8831) --- updated-dependencies: - dependency-name: trufflesecurity/trufflehog dependency-version: 3.97.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 29, 2026, 9:40 PM ET / September 30, 2026, 01:40 UTC (Revision 2). ClawSweeper reviewWhat this changesUpdates the GitHub secret-scanning action from TruffleHog 3.97.5 to 3.97.9 and records the update in the unreleased changelog. Merge readiness✅ Ready for maintainer review Current Priority: P3 Review scores
Verification
How this fits togetherThe repository's GitHub workflow scans commits from pushes and pull requests for verified secrets. It selects a commit range, runs the pinned TruffleHog action, and reports a GitHub check result. flowchart LR
A[Push or pull request] --> B[Select commit range]
B --> C[TruffleHog action]
C --> D[Check for verified secrets]
D --> E[GitHub check result]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep the verified release SHA pinned and let the existing secret-scan workflow validate the update. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates a CI dependency rather than reporting a reproducible product defect. Is this the best way to solve the issue? Yes: the SHA matches the upstream v3.97.9 tag, and the workflow retains its existing inputs and scan range. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 66a97e2e6346. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
steipete
left a comment
There was a problem hiding this comment.
Reviewed head ccb0328. The new pin matches the published TruffleHog v3.97.9 tag. Codex review found no actionable P0/P1 findings. Build, tidy, formatting, vet, vulnerability/dead-code/workflow checks, CLI smoke, snapshot packaging, the full regular suite, and the full Linux race suite passed; all checks on this head are green.
Bumps trufflesecurity/trufflehog from 3.97.5 to 3.97.9.
Release notes
Sourced from trufflesecurity/trufflehog's releases.
Commits
4dd8831Spruce up Makefile a little (#5347)449d8a3Int 595 auth errors (#5259)bad9901Add version and comment_number lines to SharePoint source metadata (#5348)4b8eb0emake 401s for Basic auth verified false. (#5290)bbf9447Update module github.com/gabriel-vasile/mimetype to v1.4.15 (#5283)16b566bUpdate module github.com/aymanbagabas/go-osc52 to v1.2.2 (#5252)a25ff85ci: scope Smoke timeouts to trufflehog runs, not the build (#5317)ca9d3b3[SCAN-162] Add Err() to JobProgress and JobProgressRef (#5346)a5f3de5Set all verification errors in detectors (#5253)7ee4d49Add per detector verification timing to verification cache (#5341)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)