actions-dev-kit
actions-dev-kit copied to clipboard
build(deps): bump trufflesecurity/trufflehog from 3.63.1 to 3.81.9
Bumps trufflesecurity/trufflehog from 3.63.1 to 3.81.9.
Release notes
Sourced from trufflesecurity/trufflehog's releases.
v3.81.9
What's Changed
- Capture decoding time metric by
@rosecodymin trufflesecurity/trufflehog#3209- fix(deps): update module cloud.google.com/go/secretmanager to v1.13.6 by
@renovatein trufflesecurity/trufflehog#3208- remove two letter keyword by
@0x1in trufflesecurity/trufflehog#3210- Add metrics for command invocation by
@mcastorinain trufflesecurity/trufflehog#3185- chore(deps): update sigstore/cosign-installer action to v3.6.0 by
@renovatein trufflesecurity/trufflehog#3211- [analyze] Capture the hierarchy of GitHub permissions by
@mcastorinain trufflesecurity/trufflehog#3127- [analyze] Fix GitHub token expiration parsing by
@mcastorinain trufflesecurity/trufflehog#3205- [chore] Fix lint errors by
@mcastorinain trufflesecurity/trufflehog#3218- [chore] Ignore analyzer implementation tests in test-community by
@mcastorinain trufflesecurity/trufflehog#3219- Support for kebab case and dot notation in permission generation tool by
@abmussaniin trufflesecurity/trufflehog#3222- Improve domain / url handling in detectors by
@dustin-deckerin trufflesecurity/trufflehog#3221Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.81.8...v3.81.9
v3.81.8
What's Changed
- [analyze] Deduplicate finegrained GitHub permissions by
@mcastorinain trufflesecurity/trufflehog#3196- fix(deps): update module golang.org/x/net to v0.28.0 by
@renovatein trufflesecurity/trufflehog#3187- [analyze] Fix double-print in postgres analyzer by
@mcastorinain trufflesecurity/trufflehog#3199- fix(deps): update module go.mongodb.org/mongo-driver to v1.16.1 by
@renovatein trufflesecurity/trufflehog#3197- Log when a detector ignores the timeout by
@rosecodymin trufflesecurity/trufflehog#3201- [bug] - Correctly Handle Large Files in BufferedReadSeeker by
@ahravin trufflesecurity/trufflehog#3203- fix(deps): update module github.com/google/go-containerregistry to v0.20.2 by
@renovatein trufflesecurity/trufflehog#3184Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.81.7...v3.81.8
v3.81.7
What's Changed
- fix(deps): update module golang.org/x/crypto to v0.26.0 by
@renovatein trufflesecurity/trufflehog#3182- fix(deps): update module golang.org/x/text to v0.17.0 - autoclosed by
@renovatein trufflesecurity/trufflehog#3183- [analyze] Add analyze option to main TUI and unhide subcommand by
@mcastorinain trufflesecurity/trufflehog#3186- Analyzer capitalization by
@hxnykin trufflesecurity/trufflehog#3188- [analyze] Bandaid solution for occasional slow startups by
@mcastorinain trufflesecurity/trufflehog#3191- [analyze] Add basic section to README by
@mcastorinain trufflesecurity/trufflehog#3190- Fixes for a few finegrained token issues by
@dustin-deckerin trufflesecurity/trufflehog#3194Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.81.6...v3.81.7
v3.81.6
What's Changed
- Auth GitHub in Init by
@rosecodymin trufflesecurity/trufflehog#3131- fix(deps): update module github.com/envoyproxy/protoc-gen-validate to v1.1.0 by
@renovatein trufflesecurity/trufflehog#3176- Analyze TUI by
@mcastorinain trufflesecurity/trufflehog#3172- [analyze] Separate SID from token in twilio analyzer by
@mcastorinain trufflesecurity/trufflehog#3177- [chore] Use custom HTTP client in sendgrid analyzer by
@mcastorinain trufflesecurity/trufflehog#3178
... (truncated)
Commits
fe5624cImprove domain / url handling in detectors (#3221)e8a297fSupport for kebab case and dot notation in permission generation tool (#3222)daa45cf[chore] Ignore analyzer implementation tests in test-community (#3219)3db9ed7[chore] Fix lint errors (#3218)c381e90[analyze] Fix GitHub token expiration parsing (#3205)baf642e[analyze] Capture the hierarchy of GitHub permissions (#3127)0ba37dbchore(deps): update sigstore/cosign-installer action to v3.6.0 (#3211)97f8a48Add metrics for command invocation (#3185)8cf1ec2remove two letter keyword (#3210)e9f8123fix(deps): update module cloud.google.com/go/secretmanager to v1.13.6 (#3208)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)