diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index d2fd5bf..ed017a1 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -78,7 +78,7 @@ jobs: # the repo's git history while running, which is exactly the kind # of third-party action GitHub recommends pinning by commit SHA. # Bumped via Dependabot's github-actions ecosystem. - uses: trufflesecurity/trufflehog@d411fff7b8879a62509f3fa98c07f247ac089a51 # v3.95.5 + uses: trufflesecurity/trufflehog@f446421baf832d6356c42c1743d99abff52ff334 # v3.95.7 with: # --only-verified: a "secret" is only flagged when TruffleHog # successfully validates it against the actual service (e.g. a