From 1d210a2590501e4a5e17cc059945c08ebcfc724b Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Tue, 25 Feb 2025 08:16:41 -0500
Subject: [PATCH] chore: bump trufflesecurity/trufflehog from 3.88.12 to
3.88.13 (#1876)
Bumps
[trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog)
from 3.88.12 to 3.88.13.
Commits
03e8af1
[Feat] DigitalOcean Analyzer (#3932)
8724d50
Remove duplicate github.com/golang-jwt/jwt
dependency (#3930)
6f1e918
Postman workspace enumeration (#3925)
faa67f4
fix(deps): update module github.com/xo/dburl to v0.23.3 (#3898)
643c382
fix(deps): update module github.com/google/go-containerregistry to
v0.20.3 (#...
- See full diff in compare
view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
.github/workflows/secret-scan.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml
index 341096ba..3760238f 100644
--- a/.github/workflows/secret-scan.yml
+++ b/.github/workflows/secret-scan.yml
@@ -23,6 +23,6 @@ jobs:
with:
fetch-depth: 0
- name: Default Secret Scanning
- uses: trufflesecurity/trufflehog@a2a17cd73d74376209d6323c80a9a55b424e25b0 # main
+ uses: trufflesecurity/trufflehog@03e8af1075a7f7410664de9f6a1101268c9c8c92 # main
with:
extra_args: --debug --no-verification # Warn on potential violations