diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index d2fd5bf..6024b63 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -78,7 +78,7 @@ jobs: # the repo's git history while running, which is exactly the kind # of third-party action GitHub recommends pinning by commit SHA. # Bumped via Dependabot's github-actions ecosystem. - uses: trufflesecurity/trufflehog@d411fff7b8879a62509f3fa98c07f247ac089a51 # v3.95.5 + uses: trufflesecurity/trufflehog@00155c9dc586f34d189adc83d3ac2698c2ec551f # v3.95.8 with: # --only-verified: a "secret" is only flagged when TruffleHog # successfully validates it against the actual service (e.g. a