Skip to content

chore(deps): bump the actions group with 2 updates - #101

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-932ff55cda
Sep 12, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-932ff55cda

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates: trufflesecurity/trufflehog and hyperpolymath/smtp-notify-action.

Updates trufflesecurity/trufflehog from 3.97.2 to 3.97.4

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.4

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.3...v3.97.4

v3.97.3

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.2...v3.97.3

Commits
  • 363923b added tests for twilio detector fixes (#5271)
  • f537081 Improve the json-enumerator source (#5265)
  • 8a9a4c6 Made retry exaustion indeterminate for Twilio secrets and twilioapikeys (#5267)
  • 8947a7f Revert "De-base64 SourceUnit.UnitData in the GitHub Source (#5248)" (#5269)
  • ea33cd0 fix(s3): cut a child context per object so key/size log values don't pile up ...
  • See full diff in compare view

Updates hyperpolymath/smtp-notify-action from 0.1.0 to 0.2.0

Release notes

Sourced from hyperpolymath/smtp-notify-action's releases.

v0.2.0

Static, byte-reproducible smtp-notify binaries. CI rebuilt them from this tag and verified they hash to exactly the SHA-256 pins inside this tag's action.yml before publishing.

Changelog

Sourced from hyperpolymath/smtp-notify-action's changelog.

// SPDX-License-Identifier: MPL-2.0 = Changelog :toc: macro :toclevels: 2

All notable changes to this action are recorded here. The format follows https://keepachangelog.com/en/1.1.0/[Keep a Changelog]; versions follow https://semver.org/spec/v2.0.0.html[Semantic Versioning].

The unit of release is the action ref: the tag or commit you pin determines both action.yml and, through the SHA-256 pins inside it, the exact binary that runs.

toc::[]

== v0.3.0 — 2026-09-09

[IMPORTANT]

main is not a release, and pinning @main is not supported.

Between a release commit landing on main and its tag being pushed, action.yml on main names assets that do not exist yet, so @main fails at the download step. This window is unavoidable rather than an oversight: the release workflow refuses to publish unless the asset URL in the tagged commit already names the tag being released, so the commit must precede the tag. The window is minutes long and is one more reason @main is not a supported ref.

Pin a tag, or a commit SHA that is an ancestor of one.

=== Added

  • STARTTLS on the submission port. secure: false or secure: starttls now starts in the clear on port 587 and upgrades the same connection in place per RFC 3207, including the mandatory second EHLO after the upgrade. The upgrade is not opportunistic: a server that does not advertise STARTTLS fails the step, and that check runs before the command is sent, so no credential is ever written to a cleartext stream. Certificate verification is identical on both TLS paths.
  • EHLO capability parsing (issue #9). The EHLO reply is parsed into a Capabilities value — STARTTLS, the AUTH mechanism list (including the Exchange AUTH=LOGIN spelling), SIZE and 8BITMIME — and an AUTH failure now names what the server actually advertised. A mechanism mismatch and a wrong password no longer look alike in the log.
  • The proven state machine now carries two tables, selected by transport, each proven separately: the implicit-TLS table is proven to contain no upgrade rows, and the STARTTLS table is proven to reach them from the start state. A row that is present but unreachable would have authenticated in the clear while every prior proof stayed green.
  • AUTH LOGIN, and mechanism selection (issue #10). The mechanism is chosen

... (truncated)

Commits
  • ede1191 docs: restore the "@​main is not a release" statement, and say why (#15)
  • ea60deb release: v0.2.0 — action.yml fetches the fixed binaries (#14)
  • 93ee757 docs: security policy, contributing guide and changelog (#13)
  • 4077691 fix: fail-closed transport, OS gate, server reply text, whole-run watchdog (#12)
  • 5730180 docs: defect registers — Bustfile (dependencies) and known defects (ours) (#11)
  • f3d5c1a docs: migration guide from dawidd6/action-send-mail (#8)
  • 6d6147e docs: describe the dawidd6 relationship honestly (#7)
  • f9809b1 fix(ci): strip CRLF from mailpit raw fetch before whole-line greps
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 2 updates: [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) and [hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action).


Updates `trufflesecurity/trufflehog` from 3.97.2 to 3.97.4
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@cc1fe98...363923b)

Updates `hyperpolymath/smtp-notify-action` from 0.1.0 to 0.2.0
- [Release notes](https://github.com/hyperpolymath/smtp-notify-action/releases)
- [Changelog](https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc)
- [Commits](hyperpolymath/smtp-notify-action@1b3b752...ede1191)

---
updated-dependencies:
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: hyperpolymath/smtp-notify-action
  dependency-version: 0.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 11, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner September 11, 2026 04:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 11, 2026
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a3fe3638-e3f8-48c2-b83f-0f2f53a7357b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 8a08299 into main Sep 12, 2026
3 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-932ff55cda branch September 12, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant