Bump trufflesecurity/trufflehog from 3.88.34 to 3.90.8
Closed
Number: #83
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: Unknown
Comments: 1
Association: Unknown
Comments: 1
Created:
September 22, 2025 at 01:25 PM UTC
(9 months ago)
(9 months ago)
Updated:
October 20, 2025 at 01:56 PM UTC
(8 months ago)
(8 months ago)
Closed:
October 20, 2025 at 01:56 PM UTC
(8 months ago)
(8 months ago)
Time to Close:
28 days
Labels:
dependencies github_actions
dependencies github_actions
Description:
Bumps trufflesecurity/trufflehog from 3.88.34 to 3.90.8.
Release notes
Sourced from trufflesecurity/trufflehog's releases.
v3.90.8
What's Changed
- Pre-filter GitHub v1 findings to prevent large numbers of validation requests by
@trufflesteeevein trufflesecurity/trufflehog#4468Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.90.7...v3.90.8
v3.90.7
What's Changed
- Fix nondeterminism in custom detectors by
@bradlarsenin trufflesecurity/trufflehog#4446- fix(deps): update aws-sdk-go-v2 monorepo by
@renovate[bot] in trufflesecurity/trufflehog#4433- fix(deps): update module github.com/couchbase/gocb/v2 to v2.11.0 by
@renovate[bot] in trufflesecurity/trufflehog#4455- fix(deps): update module google.golang.org/protobuf to v1.36.9 by
@renovate[bot] in trufflesecurity/trufflehog#4456- fix(deps): update module github.com/brianvoe/gofakeit/v7 to v7.6.0 by
@renovate[bot] in trufflesecurity/trufflehog#4457- [Feature] Fixed And Updated FlightLabs API Detector by
@nabeelalamin trufflesecurity/trufflehog#4393- Revert "Improved and fixed copper detector (#4394)" by
@camgunzin trufflesecurity/trufflehog#4470- Add metrics to SaneHTTPClient by
@amanfcpin trufflesecurity/trufflehog#4471Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.90.6...v3.90.7
v3.90.6
What's Changed
- Added support for indeterminate verification for letter Q detectors by
@patidartanayin trufflesecurity/trufflehog#4398- [Detector] rippling detector for phrase api tokens by
@SyedAliHamadin trufflesecurity/trufflehog#4348- Added explicit secrets manager write flag to Bitbucket source proto and generate new files by
@casey-tranin trufflesecurity/trufflehog#4403- [Feature] Updated Dotmailer Detector To Dotdigital by
@nabeelalamin trufflesecurity/trufflehog#4331- Add support for AWS account allow and deny lists by
@dustin-deckerin trufflesecurity/trufflehog#4407- Enable cloning repository to a specified location with retention option by
@kashifkhan0771in trufflesecurity/trufflehog#4408- fix(deps): update module google.golang.org/protobuf to v1.36.8 by
@renovate[bot] in trufflesecurity/trufflehog#4397- fix(deps): update module cloud.google.com/go/storage to v1.56.1 by
@renovate[bot] in trufflesecurity/trufflehog#4412- added flyio detector by
@lonmarsDevin trufflesecurity/trufflehog#2381- Added a dedicated optional flag to ignore gists during scan by
@kashifkhan0771in trufflesecurity/trufflehog#4423- Fix git tests if run with global commit.gpgsign=true by
@mariduvin trufflesecurity/trufflehog#4415- Recover logger if wrapped by a non-logging context implementation by
@mcastorinain trufflesecurity/trufflehog#4406- fix(deps): update aws-sdk-go-v2 monorepo by
@renovate[bot] in trufflesecurity/trufflehog#4422- fix(deps): update module github.com/gabriel-vasile/mimetype to v1.4.10 by
@renovate[bot] in trufflesecurity/trufflehog#4424- [GitHub] Add a GraphQL client to the connector by
@rgmzin trufflesecurity/trufflehog#3837- Added support for additional validation rules in custom detector by
@kashifkhan0771in trufflesecurity/trufflehog#4413- Ignore known common prefix matches for Github V1 detector by
@kashifkhan0771in trufflesecurity/trufflehog#4379- Fix error propagation and a typo in verification logic by
@bradlarsenin trufflesecurity/trufflehog#4427- [Feature] Added Detector for the Photoroom API by
@nabeelalamin trufflesecurity/trufflehog#4414- Scan Github Private Repositories With Token by
@kashifkhan0771in trufflesecurity/trufflehog#4426- fix(deps): update module github.com/brianvoe/gofakeit/v7 to v7.5.1 by
@renovate[bot] in trufflesecurity/trufflehog#4425- fix(deps): update module github.com/jedib0t/go-pretty/v6 to v6.6.8 by
@renovate[bot] in trufflesecurity/trufflehog#4396- Fix legacy json flag for Github and Gitlab private repos by
@shahzadhaider1in trufflesecurity/trufflehog#4386- Changes to fix Enterprise UI filtering of Github Hosted Scanner Repositories to Include by
@jordanTunstillin trufflesecurity/trufflehog#4430- pkg: fix some typos in comment by
@vetclippyin trufflesecurity/trufflehog#4440- Added feature flag to configure projects per page in gitlab enumeration by
@kashifkhan0771in trufflesecurity/trufflehog#4437
... (truncated)
Commits
466da5bPre-filter GitHub v1 findings to prevent large numbers of validation requests...9adec3cAdd metrics to SaneHTTPClient (#4471)cc50239Revert "Improved and fixed copper detector (#4394)" (#4470)bd45a70updated the flightlabs api detector (#4393)a1cee48fix(deps): update module github.com/brianvoe/gofakeit/v7 to v7.6.0 (#4457)3b8d23cfix(deps): update module google.golang.org/protobuf to v1.36.9 (#4456)6f619b7fix(deps): update module github.com/couchbase/gocb/v2 to v2.11.0 (#4455)989e806fix(deps): update aws-sdk-go-v2 monorepo (#4433)7f32919Fix nondeterminism in custom detectors (#4446)18c7b1fAdded feature flag to configure projects per page in gitlab enumeration (#4437)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Package:
trufflesecurity/trufflehog
Ecosystem:
actions
actions
Version Change:
3.88.34 → 3.90.8
Update Type:
Minor
Minor
Technical Details
| ID: | 10343417 |
| UUID: | 3441002244 |
| Node ID: | PR_kwDOOODVq86p2Gjz |
| Host: | GitHub |
| Repository: | TMHSDigital/Github-Demo-Repo |