This release includes 1 breaking change for platform teams planning a safe upgrade.
Published 24d
Vulnerability Scanning
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
credentials
security
dynamic-analysis
precommit
scanning
secret
+4 more
secrets-management
security-tools
trufflehog
verification
Affected surfaces
auth
rbac
Summary
AI summaryRemoved "unauthorized" exception for rotated Grafana secrets, fixing a breaking change.
Full changelog
What's Changed
- removed "unauthorized" as exception for rotated graphana secrets by @jordanTunstill in https://github.com/trufflesecurity/trufflehog/pull/5068
- fix(azuresastoken): match SAS tokens regardless of parameter order by @genisis0x in https://github.com/trufflesecurity/trufflehog/pull/5043
- Add prometheus metrics for engine channels and workers by @mcastorina in https://github.com/trufflesecurity/trufflehog/pull/5095
- [INS-465] Skip unverified JWT Detector results when feature flag is enabled by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/5072
- [INS-334] Octopus Deploy detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4787
- Fix Syntax error in feature.go by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/5109
- Include encoded resume info instead of clobbering it by @bill-rich in https://github.com/trufflesecurity/trufflehog/pull/5110
Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.95.7...v3.95.8
Breaking Changes
- Removed "unauthorized" as an allowed exception for rotated Grafana secrets
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v3.95.3 AnalysisInfo field renamed to SecretParts on Result API
Beta — feedback welcome: [email protected]