Skip to content

fix(deps): bump trufflesecurity/trufflehog from 3.97.5 to 3.97.9 - #830

Merged
d-oit merged 2 commits into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.97.9
Sep 30, 2026
Merged

d-oit merged 2 commits into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.97.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps trufflesecurity/trufflehog from 3.97.5 to 3.97.9.

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.9

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.8...v3.97.9

v3.97.8

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.7...v3.97.8

v3.97.7

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.6...v3.97.7

v3.97.6

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.5...v3.97.6

Commits
  • 4dd8831 Spruce up Makefile a little (#5347)
  • 449d8a3 Int 595 auth errors (#5259)
  • bad9901 Add version and comment_number lines to SharePoint source metadata (#5348)
  • 4b8eb0e make 401s for Basic auth verified false. (#5290)
  • bbf9447 Update module github.com/gabriel-vasile/mimetype to v1.4.15 (#5283)
  • 16b566b Update module github.com/aymanbagabas/go-osc52 to v1.2.2 (#5252)
  • a25ff85 ci: scope Smoke timeouts to trufflehog runs, not the build (#5317)
  • ca9d3b3 [SCAN-162] Add Err() to JobProgress and JobProgressRef (#5346)
  • a5f3de5 Set all verification errors in detectors (#5253)
  • 7ee4d49 Add per detector verification timing to verification cache (#5341)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 29, 2026
@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Ready Ready Preview, v0 Sep 30, 2026 3:22pm UTC

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["Dependency Verify","Quality Gate","Unit Tests","Codacy Static Code Analysis","Diagnose Blocked Merge State","Shell Script Security Analysis","Infrastructure as Code Security","Trivy Filesystem Security Scan","Dependency Advisory Audit","GitHub Actions Workflow Validation","commitlint","Analyze (javascript-typescript)","Analyze (actions)","GitNexus"]

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #830

No issues found in 1 changed file. (target branch indexed; the incoming branch is not, so cross-branch structure came from the diff alone)

Summary

A narrowly scoped security workflow dependency update with no graph-traced downstream reach, but elevated file risk.

🟠 HIGH blast radius. This appears to be a GitHub Actions dependency update in .github/workflows/security-scan.yml, with no graph-traced dependents.

The change bumps trufflesecurity/trufflehog from 3.97.5 to 3.97.9. Review the dependency reference and surrounding configuration in .github/workflows/security-scan.yml, which is the HIGH risk file.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #830

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟠 HIGH blast radius — no downstream dependents were found in the code graph; review the dependent list before merging. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟠 HIGH 0 0 1

What changed

Changed Files (1)
File Status
.github/workflows/security-scan.yml 🟡 modified

What to check

File Risk (1)
File Risk Category
.github/workflows/security-scan.yml 🟠 HIGH CI/CD

Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.97.5 to 3.97.9.
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@f714bf4...4dd8831)

---
updated-dependencies:
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/trufflesecurity/trufflehog-3.97.9 branch from 4333f35 to ee51511 Compare September 30, 2026 09:20
@d-oit
d-oit enabled auto-merge (squash) September 30, 2026 15:21
@d-oit
d-oit merged commit 10d7181 into main Sep 30, 2026
25 checks passed
@d-oit
d-oit deleted the dependabot/github_actions/trufflesecurity/trufflehog-3.97.9 branch September 30, 2026 15:23

This branch was successfully deployed

1 active deployment
Preview — 119fa5f4 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci config dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant