Repository navigation
build(deps): update TruffleHog to v3.98.0 - #235
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. What this changesThis PR updates the TruffleHog GitHub Action reference to v3.98.0 and records it under Unreleased. Example: A pull request triggers the verified-secret scanning workflow.
Review scores
ProductKind: Maintenance · Worth it: Yes · Fix scope: Complete Merge readiness✅ Ready for maintainer review Keep this PR open: current main still references v3.97.9, and the verified v3.98.0 action-reference update introduces no actionable defect. Priority: P3 Before mergeNone. FindingsNone. Agent review detailsHow this fits togetherGitHub push and pull-request events supply commit ranges to the secret-scanning workflow, which invokes TruffleHog and fails when verified credentials are found. flowchart LR
A[GitHub event] --> B[Repository checkout]
B --> C[Resolve commit range]
C --> D[Pinned TruffleHog action]
D --> E[Latest scanner Docker image]
E --> F[Scan result]
Technical reviewBest possible solution: Land the verified action-reference refresh through the repository's existing merge gates. Do we have a high-confidence way to reproduce the issue? No bug is reported; source inspection confirms the reference update and identical executable action wrapper. Is this the best way to solve the issue? Refreshing the existing SHA pin preserves the established workflow without adding another scanning path or changing scanner-version policy. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against bf6fa23eecac. Provenance checked
TestingProof path: none. SecurityNone. EvidenceWhat I checked:
Likely related people:
LabelsLabel changes: No label changes. Label justifications:
Rating scale6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior. WorkflowClawSweeper edits this one comment on every review. Comment HistoryReview history (7 earlier review cycles)
Reviewed October 10, 2026, 6:16 AM ET / 10:16 UTC (Revision 8). |
Refresh the pinned secret-scanning action and record the update in Unreleased. Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
c57082b to
80aba87
Compare
Updates the pinned TruffleHog GitHub Action from v3.97.9 to v3.98.0 while retaining the existing scan configuration. Adds an Unreleased entry and preserves Dependabot's contribution. Rebased onto current main.
Validation completed on Go 1.27.2, Node 26.10.0, and GoReleaser 2.18.2:
GOWORK=off make checkpassed, including vet, deadcode, 85.2% coverage, CLI smoke tests, release-script tests, docs, and six-platform snapshot builds.govulncheck ./...: no vulnerabilities found.GOEXPERIMENT=simdtests and scalar-fallback tests forinternal/vectorandinternal/cli: passed.Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>