diff --git a/.github/workflows/secret-scan-scheduled.yml b/.github/workflows/secret-scan-scheduled.yml index a415a6c..7ee820d 100644 --- a/.github/workflows/secret-scan-scheduled.yml +++ b/.github/workflows/secret-scan-scheduled.yml @@ -33,7 +33,7 @@ jobs: fetch-depth: 0 # full history — the whole point of the scheduled scan persist-credentials: false - name: TruffleHog (full history, all result tiers) - uses: trufflesecurity/trufflehog@363923b901c911a9164f50b6c423f47c15372b1c # v3.97.4 + uses: trufflesecurity/trufflehog@f714bf454f350590f4a24c3ddb1aef02c35bf5b6 # v3.97.5 with: path: ./ # Pinned. The action's `version` input defaults to "latest" and it runs @@ -50,7 +50,7 @@ jobs: # actually scanned. Resolved forward onto the ref. Every Dependabot # bump of the `uses:` pin therefore has to carry this input with it; # tests/secret-scan-workflow.test.ts is what stops one that does not. - version: "3.97.4" + version: "3.97.5" # The note that used to sit here said `version` was deliberately left at # "latest" because ghcr.io had not yet published an image tag matching the # action's release, and that a stale numbered tag drifting from the action