This release adds 4 notable features for engineering teams evaluating rollout.
Published 27d
Vulnerability Scanning
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
credentials
security
dynamic-analysis
precommit
scanning
secret
+4 more
secrets-management
security-tools
trufflehog
verification
Affected surfaces
auth
rbac
Summary
AI summaryUpdates sources, filesystem, and sources/filesystem across a mixed release.
Full changelog
What's Changed
- fix(sources/filesystem): order resume comparison by path component by @genisis0x in https://github.com/trufflesecurity/trufflehog/pull/5041
- test(handlers): point APK test fixture at trufflehog-test-assets by @amanfcp in https://github.com/trufflesecurity/trufflehog/pull/5053
- fixed regex typo that was causing conf uuid's to be surfaced as non-live atlassian secrets. by @jordanTunstill in https://github.com/trufflesecurity/trufflehog/pull/5029
- Fix GitHub App cross-org member enumeration using per-installation tokens by @dustin-decker in https://github.com/trufflesecurity/trufflehog/pull/4774
- fix: add git worktree support in PrepareRepo by @andoniaf in https://github.com/trufflesecurity/trufflehog/pull/4690
- [INS-406] Braintrust detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4826
- huggingface: add bucket scanning by @julien-c in https://github.com/trufflesecurity/trufflehog/pull/5017
- Skip reverification results during deduplication by @mcastorina in https://github.com/trufflesecurity/trufflehog/pull/5069
- chore(renovate): bump shared config to v1.0.3 by @bryanbeverly in https://github.com/trufflesecurity/trufflehog/pull/5044
- Add scan_all_installations option for multi-org GitHub App scanning by @dustin-decker in https://github.com/trufflesecurity/trufflehog/pull/4775
- Expose
SecretPartsin the JSON output by @bradlarsen in https://github.com/trufflesecurity/trufflehog/pull/5073 - [INS-497] Add Pganalyze Read Key Detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4993
- [INS-197] Add redhatpyxis api key detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4995
- [INS-407] Fixed AWS detector producing non deterministic output by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4836
New Contributors
- @genisis0x made their first contribution in https://github.com/trufflesecurity/trufflehog/pull/5041
- @andoniaf made their first contribution in https://github.com/trufflesecurity/trufflehog/pull/4690
- @julien-c made their first contribution in https://github.com/trufflesecurity/trufflehog/pull/5017
Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.95.6...v3.95.7
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v3.95.3 AnalysisInfo field renamed to SecretParts on Result API
Beta — feedback welcome: [email protected]