Skip to content

build(deps): update TruffleHog to v3.98.0 - #235

Merged
steipete merged 1 commit into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.98.0
Oct 10, 2026
Merged

steipete merged 1 commit into
mainfrom
dependabot/github_actions/trufflesecurity/trufflehog-3.98.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Updates the pinned TruffleHog GitHub Action from v3.97.9 to v3.98.0 while retaining the existing scan configuration. Adds an Unreleased entry and preserves Dependabot's contribution. Rebased onto current main.

Validation completed on Go 1.27.2, Node 26.10.0, and GoReleaser 2.18.2:

  • Independent AutoReview: no actionable P0–P3 findings.
  • AWS Crabbox: full GOWORK=off make check passed, including vet, deadcode, 85.2% coverage, CLI smoke tests, release-script tests, docs, and six-platform snapshot builds.
  • govulncheck ./...: no vulnerabilities found.
  • Full GOEXPERIMENT=simd tests and scalar-fallback tests for internal/vector and internal/cli: passed.

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 8, 2026 18:45
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026
@clawsweeper

clawsweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 8, 2026
@clawsweeper

clawsweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge.

What this changes

This PR updates the TruffleHog GitHub Action reference to v3.98.0 and records it under Unreleased.

Example: A pull request triggers the verified-secret scanning workflow.

  • Before: GitHub loads the action from commit 4dd8831c5f12599465d4d45c3c447b4018a34c85.
  • After: GitHub loads the action from commit 0186870afd2c4a90def791d80260923ba583d076; its identical wrapper still runs the latest scanner Docker image.

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, source-verified dependency-reference update with successful scan validation and no actionable findings.
Proof confidence 🐚 platinum hermit (4/6) This bot-authored maintenance PR is outside the ordinary contributor proof gate; identical action source and successful exact-head scan jobs support validation without treating CI as live-behavior proof.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Product

Kind: Maintenance · Worth it: Yes · Fix scope: Complete
User problem: The workflow's action reference trails the available upstream release.
Reason: This small refresh continues established dependency maintenance while preserving action behavior and SHA pinning.

Merge readiness

✅ Ready for maintainer review

Keep this PR open: current main still references v3.97.9, and the verified v3.98.0 action-reference update introduces no actionable defect.

Priority: P3
Reviewed head: 80aba8783c19131a7a174b464d9a4e7ebe8f13e7

Before merge

None.

Findings

None.

Agent review details

How this fits together

GitHub push and pull-request events supply commit ranges to the secret-scanning workflow, which invokes TruffleHog and fails when verified credentials are found.

flowchart LR
  A[GitHub event] --> B[Repository checkout]
  B --> C[Resolve commit range]
  C --> D[Pinned TruffleHog action]
  D --> E[Latest scanner Docker image]
  E --> F[Scan result]
Loading

Technical review

Best possible solution:

Land the verified action-reference refresh through the repository's existing merge gates.

Do we have a high-confidence way to reproduce the issue?

No bug is reported; source inspection confirms the reference update and identical executable action wrapper.

Is this the best way to solve the issue?

Refreshing the existing SHA pin preserves the established workflow without adding another scanning path or changing scanner-version policy.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against bf6fa23eecac.

Provenance checked

  • Secret-scanning action reference keeps the original intent (21b91a1: The prior merged maintenance PR refreshed the scanner action while retaining the existing workflow and compatibility floor.)

Testing

Proof path: none.

Security

None.

Evidence

What I checked:

Likely related people:

  • Vincent Koc: Raw commit a4ab91b adds .github/workflows/secret-scan.yml:13 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: a4ab91b035da; files: .github/workflows/secret-scan.yml)

Labels

Label changes:

No label changes.

Label justifications:

  • P3: Routine action-reference maintenance preserves the executable wrapper and existing scan configuration.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR.

Rating scale

6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior.

Workflow

ClawSweeper edits this one comment on every review. Comment @clawsweeper re-review for a fresh review only; repair and merge need explicit maintainer commands such as @clawsweeper autofix or @clawsweeper automerge.

History

Review history (7 earlier review cycles)
  • reviewed 2026-10-08T18:47:56.329Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T01:51:14.131Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T07:41:56.814Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T11:46:54.363Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T15:49:00.763Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T17:27:04.550Z sha c57082b :: needs maintainer review before merge. :: none
  • reviewed 2026-10-09T19:45:58.596Z sha c57082b :: needs maintainer review before merge. :: none

Reviewed October 10, 2026, 6:16 AM ET / 10:16 UTC (Revision 8).

Refresh the pinned secret-scanning action and record the update in Unreleased.

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@steipete
steipete force-pushed the dependabot/github_actions/trufflesecurity/trufflehog-3.98.0 branch from c57082b to 80aba87 Compare October 10, 2026 10:12
@steipete steipete changed the title chore(deps): bump trufflesecurity/trufflehog from 3.97.9 to 3.98.0 build(deps): update TruffleHog to v3.98.0 Oct 10, 2026
@steipete
steipete merged commit bd30790 into main Oct 10, 2026
14 checks passed
@steipete
steipete deleted the dependabot/github_actions/trufflesecurity/trufflehog-3.98.0 branch October 10, 2026 10:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant