From 03f19c080b9b2003893cab50984d448ff29dfeb2 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 02:06:57 +0000 Subject: [PATCH 1/2] chore(deps): Bump trufflesecurity/trufflehog from 3.97.4 to 3.97.5 Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.97.4 to 3.97.5. - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](https://github.com/trufflesecurity/trufflehog/compare/363923b901c911a9164f50b6c423f47c15372b1c...f714bf454f350590f4a24c3ddb1aef02c35bf5b6) --- updated-dependencies: - dependency-name: trufflesecurity/trufflehog dependency-version: 3.97.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/secret-scan-scheduled.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/secret-scan-scheduled.yml b/.github/workflows/secret-scan-scheduled.yml index a415a6c..2265425 100644 --- a/.github/workflows/secret-scan-scheduled.yml +++ b/.github/workflows/secret-scan-scheduled.yml @@ -33,7 +33,7 @@ jobs: fetch-depth: 0 # full history — the whole point of the scheduled scan persist-credentials: false - name: TruffleHog (full history, all result tiers) - uses: trufflesecurity/trufflehog@363923b901c911a9164f50b6c423f47c15372b1c # v3.97.4 + uses: trufflesecurity/trufflehog@f714bf454f350590f4a24c3ddb1aef02c35bf5b6 # v3.97.5 with: path: ./ # Pinned. The action's `version` input defaults to "latest" and it runs From 51adb84a52acd0d6c3f48b2a42810fdf25ed2651 Mon Sep 17 00:00:00 2001 From: Chelsea Kelly-Reif <3114598+ChelseaKR@users.noreply.github.com> Date: Fri, 18 Sep 2026 22:29:14 -0700 Subject: [PATCH 2/2] fix(security): move the trufflehog version input with the action ref to 3.97.5 Dependabot rewrites the uses: pin and never a with: input, so the bump left version: at 3.97.4 and tests/secret-scan-workflow.test.ts (correctly) failed the build: the scan would have kept running 3.97.4 while the ref said 3.97.5. Set both to the same release. The 3.97.5 image tag exists on ghcr.io and the action SHA is the v3.97.5 tag commit. --- .github/workflows/secret-scan-scheduled.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/secret-scan-scheduled.yml b/.github/workflows/secret-scan-scheduled.yml index 2265425..7ee820d 100644 --- a/.github/workflows/secret-scan-scheduled.yml +++ b/.github/workflows/secret-scan-scheduled.yml @@ -50,7 +50,7 @@ jobs: # actually scanned. Resolved forward onto the ref. Every Dependabot # bump of the `uses:` pin therefore has to carry this input with it; # tests/secret-scan-workflow.test.ts is what stops one that does not. - version: "3.97.4" + version: "3.97.5" # The note that used to sit here said `version` was deliberately left at # "latest" because ghcr.io had not yet published an image tag matching the # action's release, and that a stale numbered tag drifting from the action