Skip to content

ci: pin trufflesecurity/trufflehog to a full commit SHA (v3.95.9) - #14685

Merged
v-dvedak merged 1 commit into
Azure:masterfrom
kobihikri:ci/pin-trufflehog
Jul 20, 2026
Merged

v-dvedak merged 1 commit into
Azure:masterfrom
kobihikri:ci/pin-trufflehog

Conversation

@kobihikri

Copy link
Copy Markdown
Contributor

Hi, and thank you for Azure Sentinel.

Small CI supply-chain hardening, one line. ScanSecrets.yaml runs the secret scanner from a mutable branch ref:

uses: trufflesecurity/trufflehog@main

The job carries pull-requests: write and checks out PR code, so whatever trufflehog@main happens to point at executes with the repo's GITHUB_TOKEN. A branch can move after review; a full commit SHA cannot (GitHub's own hardening guidance recommends SHA-pinning third-party actions).

This PR pins it to the commit behind the current release, keeping the version visible as a comment:

uses: trufflesecurity/trufflehog@27b0417c16317ca9a472a9a8092acce143b49c55 # v3.95.9

Verified: gh api repos/trufflesecurity/trufflehog/git/ref/tags/v3.95.9 → 27b0417c…. Behavior today is unchanged; future updates become a deliberate one-line bump (Dependabot can manage SHA pins, not branch refs).

For transparency: I used AI assistance to spot and draft this; I verified the workflow content and the release SHA myself.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Pins the TruffleHog GitHub Action in the secret-scanning workflow to an immutable commit SHA to reduce CI supply-chain risk while keeping the human-readable version noted inline.

Changes:

  • Replace trufflesecurity/trufflehog@main with a full commit SHA pin
  • Preserve the release version (v3.95.9) as a comment for maintainability

@v-dvedak
v-dvedak merged commit 794547f into Azure:master Jul 20, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants