Skip to content

Commit 03afaa2

Browse files
authored
Merge branch 'main' into gha-fix
2 parents 493c511 + 8d5986d commit 03afaa2

26 files changed

+1078
-423
lines changed

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ jobs:
3838
with:
3939
go-version: "1.24"
4040
- name: Cosign install
41-
uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb # v3.8.2
41+
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9.1
4242
- name: Install UPX
4343
run: |
4444
sudo apt-get update

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ RUN --mount=type=cache,target=/go/pkg/mod \
88
--mount=type=cache,target=/root/.cache/go-build \
99
GOOS=${TARGETOS} GOARCH=${TARGETARCH} go build -o trufflehog .
1010

11-
FROM alpine:3.21
11+
FROM alpine:3.22
1212
RUN apk add --no-cache bash git openssh-client ca-certificates rpm2cpio binutils cpio \
1313
&& rm -rf /var/cache/apk/* && update-ca-certificates
1414
COPY --from=builder /build/trufflehog /usr/bin/trufflehog

Dockerfile.goreleaser

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM alpine:3.21
1+
FROM alpine:3.22
22

33
RUN apk add --no-cache bash git openssh-client ca-certificates \
44
&& rm -rf /var/cache/apk/* && update-ca-certificates

go.mod

Lines changed: 55 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
module github.com/trufflesecurity/trufflehog/v3
22

3-
go 1.23.1
3+
go 1.24
44

5-
toolchain go1.24.4
5+
toolchain go1.24.5
66

77
replace github.com/jpillora/overseer => github.com/trufflesecurity/overseer v1.2.8
88

@@ -16,22 +16,22 @@ require (
1616
github.com/TheZeroSlave/zapsentry v1.23.0
1717
github.com/adrg/strutil v0.3.1
1818
github.com/alecthomas/kingpin/v2 v2.4.0
19-
github.com/avast/apkparser v0.0.0-20250530053210-166ba1767cb9
20-
github.com/aws/aws-sdk-go-v2 v1.36.4
21-
github.com/aws/aws-sdk-go-v2/config v1.29.16
22-
github.com/aws/aws-sdk-go-v2/credentials v1.17.69
23-
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.17.79
24-
github.com/aws/aws-sdk-go-v2/service/s3 v1.80.2
25-
github.com/aws/aws-sdk-go-v2/service/sns v1.34.6
26-
github.com/aws/aws-sdk-go-v2/service/sts v1.33.21
27-
github.com/aws/smithy-go v1.22.3
19+
github.com/avast/apkparser v0.0.0-20250626104540-d53391f4d69d
20+
github.com/aws/aws-sdk-go-v2 v1.36.5
21+
github.com/aws/aws-sdk-go-v2/config v1.29.17
22+
github.com/aws/aws-sdk-go-v2/credentials v1.17.70
23+
github.com/aws/aws-sdk-go-v2/feature/s3/manager v1.17.83
24+
github.com/aws/aws-sdk-go-v2/service/s3 v1.83.0
25+
github.com/aws/aws-sdk-go-v2/service/sns v1.34.7
26+
github.com/aws/aws-sdk-go-v2/service/sts v1.34.0
27+
github.com/aws/smithy-go v1.22.4
2828
github.com/aymanbagabas/go-osc52 v1.2.1
2929
github.com/bill-rich/go-syslog v0.0.0-20220413021637-49edb52a574c
3030
github.com/bitfinexcom/bitfinex-api-go v0.0.0-20210608095005-9e0b26f200fb
3131
github.com/bradleyfalzon/ghinstallation/v2 v2.14.0
3232
github.com/brianvoe/gofakeit/v7 v7.2.1
3333
github.com/charmbracelet/bubbles v0.18.0
34-
github.com/charmbracelet/bubbletea v1.3.4
34+
github.com/charmbracelet/bubbletea v1.3.6
3535
github.com/charmbracelet/glamour v0.7.0
3636
github.com/charmbracelet/lipgloss v1.1.0
3737
github.com/coinbase/waas-client-library-go v1.0.8
@@ -55,11 +55,11 @@ require (
5555
github.com/gobwas/glob v0.2.3
5656
github.com/golang-jwt/jwt/v5 v5.2.2
5757
github.com/google/go-cmp v0.7.0
58-
github.com/google/go-containerregistry v0.20.3
58+
github.com/google/go-containerregistry v0.20.6
5959
github.com/google/go-github/v67 v67.0.0
6060
github.com/google/uuid v1.6.0
6161
github.com/googleapis/gax-go/v2 v2.14.2
62-
github.com/hashicorp/go-retryablehttp v0.7.7
62+
github.com/hashicorp/go-retryablehttp v0.7.8
6363
github.com/hashicorp/golang-lru/v2 v2.0.7
6464
github.com/jedib0t/go-pretty/v6 v6.6.7
6565
github.com/jlaffaye/ftp v0.2.0
@@ -97,17 +97,17 @@ require (
9797
github.com/testcontainers/testcontainers-go/modules/postgres v0.34.0
9898
github.com/trufflesecurity/disk-buffer-reader v0.2.1
9999
github.com/wasilibs/go-re2 v1.9.0
100-
github.com/xo/dburl v0.23.7
100+
github.com/xo/dburl v0.23.8
101101
gitlab.com/gitlab-org/api/client-go v0.127.0
102-
go.mongodb.org/mongo-driver v1.17.3
102+
go.mongodb.org/mongo-driver v1.17.4
103103
go.uber.org/automaxprocs v1.6.0
104-
go.uber.org/mock v0.5.1
104+
go.uber.org/mock v0.5.2
105105
go.uber.org/zap v1.27.0
106-
golang.org/x/crypto v0.37.0
107-
golang.org/x/net v0.39.0
106+
golang.org/x/crypto v0.39.0
107+
golang.org/x/net v0.41.0
108108
golang.org/x/oauth2 v0.30.0
109-
golang.org/x/sync v0.14.0
110-
golang.org/x/text v0.24.0
109+
golang.org/x/sync v0.15.0
110+
golang.org/x/text v0.26.0
111111
golang.org/x/time v0.11.0
112112
google.golang.org/api v0.232.0
113113
google.golang.org/protobuf v1.36.6
@@ -124,13 +124,13 @@ require (
124124
cloud.google.com/go v0.120.0 // indirect
125125
cloud.google.com/go/auth v0.16.1 // indirect
126126
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
127-
cloud.google.com/go/compute/metadata v0.6.0 // indirect
127+
cloud.google.com/go/compute/metadata v0.7.0 // indirect
128128
cloud.google.com/go/iam v1.5.2 // indirect
129129
cloud.google.com/go/longrunning v0.6.7 // indirect
130130
cloud.google.com/go/monitoring v1.24.2 // indirect
131131
dario.cat/mergo v1.0.0 // indirect
132132
filippo.io/edwards25519 v1.1.0 // indirect
133-
github.com/AdaLogics/go-fuzz-headers v0.0.0-20230811130428-ced1acdcaa24 // indirect
133+
github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6 // indirect
134134
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
135135
github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 // indirect
136136
github.com/AzureAD/microsoft-authentication-library-for-go v1.3.2 // indirect
@@ -145,18 +145,18 @@ require (
145145
github.com/alecthomas/units v0.0.0-20211218093645-b94a6e3cc137 // indirect
146146
github.com/andybalholm/brotli v1.1.1 // indirect
147147
github.com/atotto/clipboard v0.1.4 // indirect
148-
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.10 // indirect
149-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.31 // indirect
150-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.35 // indirect
151-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.35 // indirect
148+
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.11 // indirect
149+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.32 // indirect
150+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.36 // indirect
151+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.36 // indirect
152152
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
153-
github.com/aws/aws-sdk-go-v2/internal/v4a v1.3.35 // indirect
154-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
155-
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.7.3 // indirect
156-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.16 // indirect
157-
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.18.16 // indirect
158-
github.com/aws/aws-sdk-go-v2/service/sso v1.25.4 // indirect
159-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.2 // indirect
153+
github.com/aws/aws-sdk-go-v2/internal/v4a v1.3.36 // indirect
154+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.4 // indirect
155+
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.7.4 // indirect
156+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.17 // indirect
157+
github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.18.17 // indirect
158+
github.com/aws/aws-sdk-go-v2/service/sso v1.25.5 // indirect
159+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.30.3 // indirect
160160
github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
161161
github.com/aymerick/douceur v0.2.0 // indirect
162162
github.com/beorn7/perks v1.0.1 // indirect
@@ -166,11 +166,13 @@ require (
166166
github.com/cenkalti/backoff/v4 v4.2.1 // indirect
167167
github.com/cespare/xxhash/v2 v2.3.0 // indirect
168168
github.com/charmbracelet/colorprofile v0.2.3-0.20250311203215-f60798e515dc // indirect
169-
github.com/charmbracelet/x/ansi v0.8.0 // indirect
169+
github.com/charmbracelet/x/ansi v0.9.3 // indirect
170170
github.com/charmbracelet/x/cellbuf v0.0.13-0.20250311204145-2c3ea96c31dd // indirect
171171
github.com/charmbracelet/x/term v0.2.1 // indirect
172172
github.com/cloudflare/circl v1.3.8 // indirect
173173
github.com/cncf/xds/go v0.0.0-20250121191232-2f005788dc42 // indirect
174+
github.com/containerd/errdefs v1.0.0 // indirect
175+
github.com/containerd/errdefs/pkg v0.3.0 // indirect
174176
github.com/containerd/log v0.1.0 // indirect
175177
github.com/containerd/platforms v0.2.1 // indirect
176178
github.com/containerd/stargz-snapshotter/estargz v0.16.3 // indirect
@@ -183,10 +185,10 @@ require (
183185
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
184186
github.com/distribution/reference v0.6.0 // indirect
185187
github.com/dlclark/regexp2 v1.4.0 // indirect
186-
github.com/docker/cli v27.5.0+incompatible // indirect
188+
github.com/docker/cli v28.2.2+incompatible // indirect
187189
github.com/docker/distribution v2.8.3+incompatible // indirect
188-
github.com/docker/docker v27.5.0+incompatible // indirect
189-
github.com/docker/docker-credential-helpers v0.8.2 // indirect
190+
github.com/docker/docker v28.2.2+incompatible // indirect
191+
github.com/docker/docker-credential-helpers v0.9.3 // indirect
190192
github.com/docker/go-connections v0.5.0 // indirect
191193
github.com/docker/go-units v0.5.0 // indirect
192194
github.com/dsnet/compress v0.0.2-0.20230904184137-39efe44ab707 // indirect
@@ -238,9 +240,10 @@ require (
238240
github.com/mitchellh/colorstring v0.0.0-20190213212951-d06e56a500db // indirect
239241
github.com/mitchellh/go-homedir v1.1.0 // indirect
240242
github.com/moby/docker-image-spec v1.3.1 // indirect
243+
github.com/moby/go-archive v0.1.0 // indirect
241244
github.com/moby/patternmatcher v0.6.0 // indirect
242-
github.com/moby/sys/sequential v0.5.0 // indirect
243-
github.com/moby/sys/user v0.1.0 // indirect
245+
github.com/moby/sys/sequential v0.6.0 // indirect
246+
github.com/moby/sys/user v0.4.0 // indirect
244247
github.com/moby/sys/userns v0.1.0 // indirect
245248
github.com/moby/term v0.5.0 // indirect
246249
github.com/montanaflynn/stats v0.7.1 // indirect
@@ -253,7 +256,7 @@ require (
253256
github.com/olekukonko/tablewriter v0.0.5 // indirect
254257
github.com/onsi/ginkgo v1.16.5 // indirect
255258
github.com/opencontainers/go-digest v1.0.0 // indirect
256-
github.com/opencontainers/image-spec v1.1.0 // indirect
259+
github.com/opencontainers/image-spec v1.1.1 // indirect
257260
github.com/pierrec/lz4/v4 v4.1.21 // indirect
258261
github.com/pjbgf/sha1cd v0.3.2 // indirect
259262
github.com/pkg/diff v0.0.0-20200914180035-5b29258ca4f7 // indirect
@@ -279,7 +282,7 @@ require (
279282
github.com/tklauser/numcpus v0.6.1 // indirect
280283
github.com/trufflesecurity/touchfile v0.1.1 // indirect
281284
github.com/ulikunitz/xz v0.5.12 // indirect
282-
github.com/vbatts/tar-split v0.11.6 // indirect
285+
github.com/vbatts/tar-split v0.12.1 // indirect
283286
github.com/wasilibs/wazero-helpers v0.0.0-20240620070341-3dff1577cd52 // indirect
284287
github.com/xanzy/ssh-agent v0.3.3 // indirect
285288
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
@@ -297,20 +300,20 @@ require (
297300
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
298301
go.opentelemetry.io/contrib/detectors/gcp v1.34.0 // indirect
299302
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
300-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
301-
go.opentelemetry.io/otel v1.35.0 // indirect
303+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
304+
go.opentelemetry.io/otel v1.36.0 // indirect
302305
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 // indirect
303-
go.opentelemetry.io/otel/metric v1.35.0 // indirect
304-
go.opentelemetry.io/otel/sdk v1.35.0 // indirect
305-
go.opentelemetry.io/otel/sdk/metric v1.35.0 // indirect
306-
go.opentelemetry.io/otel/trace v1.35.0 // indirect
306+
go.opentelemetry.io/otel/metric v1.36.0 // indirect
307+
go.opentelemetry.io/otel/sdk v1.36.0 // indirect
308+
go.opentelemetry.io/otel/sdk/metric v1.36.0 // indirect
309+
go.opentelemetry.io/otel/trace v1.36.0 // indirect
307310
go.uber.org/multierr v1.11.0 // indirect
308311
go4.org v0.0.0-20230225012048-214862532bf5 // indirect
309312
golang.org/x/exp v0.0.0-20241217172543-b2144cdd0a67 // indirect
310-
golang.org/x/mod v0.22.0 // indirect
311-
golang.org/x/sys v0.32.0 // indirect
312-
golang.org/x/term v0.31.0 // indirect
313-
golang.org/x/tools v0.29.0 // indirect
313+
golang.org/x/mod v0.25.0 // indirect
314+
golang.org/x/sys v0.33.0 // indirect
315+
golang.org/x/term v0.32.0 // indirect
316+
golang.org/x/tools v0.34.0 // indirect
314317
google.golang.org/genproto v0.0.0-20250505200425-f936aa4a68b2 // indirect
315318
google.golang.org/genproto/googleapis/api v0.0.0-20250505200425-f936aa4a68b2 // indirect
316319
google.golang.org/genproto/googleapis/rpc v0.0.0-20250505200425-f936aa4a68b2 // indirect

0 commit comments

Comments
 (0)