This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2d
Vulnerability Scanning
✓ No known CVEs patched
This release patches 1 known CVE
Topics
credentials
security
dynamic-analysis
precommit
scanning
secret
+4 more
secrets-management
security-tools
trufflehog
verification
Affected surfaces
deps
Summary
AI summaryUpdate go‑git dependency to v5.19.1 (security) and add Duo API Secret Key Detector.
Full changelog
What's Changed
- [INS-355] Added Hashicorp vault token detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4819
- Tighten JiraToken v1 verification by @shahzadhaider1 in https://github.com/trufflesecurity/trufflehog/pull/5122
- [INT-718] Add TargetNotFoundError for targeted scan targets missing from the source by @bill-rich in https://github.com/trufflesecurity/trufflehog/pull/5123
- Fix GitLab project metadata cache and switch to LRU by @kashifkhan0771 in https://github.com/trufflesecurity/trufflehog/pull/4727
- Log analyze errors for Anthropic Analyzer by @kashifkhan0771 in https://github.com/trufflesecurity/trufflehog/pull/5120
- Add metrics for chunks and results by @mcastorina in https://github.com/trufflesecurity/trufflehog/pull/5128
- Update Cloudflare detectors for 2026+ prefixed credential formats (include upstream PR changes) by @kashifkhan0771 in https://github.com/trufflesecurity/trufflehog/pull/5111
- [INS-312] Duo API Secret Key Detector by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4771
- [Feature] Added SonarQube Cloud "Scoped Organization Token" Detector by @nabeelalam in https://github.com/trufflesecurity/trufflehog/pull/4739
- [INS-255] Updated datadog detector to set verificationError in case of a verification error by @MuneebUllahKhan222 in https://github.com/trufflesecurity/trufflehog/pull/4661
- Log analyze errors for Postgres analyzer by @kashifkhan0771 in https://github.com/trufflesecurity/trufflehog/pull/5131
- Log analyze errors for HuggingFace analyzer by @kashifkhan0771 in https://github.com/trufflesecurity/trufflehog/pull/5130
- Engine - Config.SourceManager doc by @amanfcp in https://github.com/trufflesecurity/trufflehog/pull/5002
- Update module github.com/go-git/go-git/v5 to v5.19.1 [SECURITY] by @renovate[bot] in https://github.com/trufflesecurity/trufflehog/pull/5034
- Retry git clone on transient network errors by @shahzadhaider1 in https://github.com/trufflesecurity/trufflehog/pull/5132
- Fix
scan_all_installationsRejecting Org Member Personal Repos by @shahzadhaider1 in https://github.com/trufflesecurity/trufflehog/pull/5142 - updated detector to include underscore char by @mattbrady-1 in https://github.com/trufflesecurity/trufflehog/pull/5121
- [chore] Change job_id in metric to source_type by @mcastorina in https://github.com/trufflesecurity/trufflehog/pull/5149
- Posthog regex update by @mattbrady-1 in https://github.com/trufflesecurity/trufflehog/pull/5133
- fix(handlers): apk handler now doesnt check for apk extension since json-enumerator and other byte stream methods wouldnt have it by @johannestaas-trufflesec in https://github.com/trufflesecurity/trufflehog/pull/5151
New Contributors
- @mattbrady-1 made their first contribution in https://github.com/trufflesecurity/trufflehog/pull/5121
Full Changelog: https://github.com/trufflesecurity/trufflehog/compare/v3.95.9...v3.96.0
Security Fixes
- SECURITY: Update module github.com/go-git/go-git/v5 to v5.19.1 (includes security fixes)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v3.95.3 AnalysisInfo field renamed to SecretParts on Result API
Beta — feedback welcome: [email protected]