💾 IT Security Tools 🕛 vor 2 Std. 2 Min Lesezeit SECURITY-FEED
0

GitHub Release: trufflesecurity/trufflehog v3.97.5 (16.09.2026)

↗ Quelle (GitHub · trufflesecurity/trufflehog)
🗣️ Stimme:
GitHub Release: trufflesecurity/trufflehog v3.97.5 (16.09.2026)
📑 Inhaltsübersicht
Avatar
$ git clone https://github.com/trufflesecurity/trufflehog.git

What's Changed



  • Update module github.com/rabbitmq/amqp091-go to v1.13.0 [SECURITY] by

  • Update github-actions by

  • Update dependency golangci/golangci-lint to v2.13.2 by

  • Make GitHub App installationId optional when scanning all installations by

  • [INT-942] Add HumioAPIToken detector by

  • Object filtering in S3 by

  • feat(detectors): add Resend detector by

  • Clean up use of wasilibs/go-re2 by

  • Low-memory Git Scanning by

  • Adding no-ignore flag to allow reporting of "ignored" secrets by

  • Postgres: drop non-connection URI params before verifying by

  • fix(detectors/ngrok): broaden valid bearer tokens matching by

  • ci: avoid Node 20 BuildPulse action by

  • Introduce a new optional detector interface that will allow us to verify credentials not in the cache by

  • perf(engine): lowercase prefilter chunks as ASCII in a pooled buffer by

  • Add documentation for CircleCI source by

  • Add filesystem source documentation by

  • Add elasticsearch source documentation by

  • [SCAN-177] Purge secret parts from verification cache by


New Contributors






Full Changelog: v3.97.4...v3.97.5

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
9 Quellen
CVE-2022-44169 | Tenda AC15 15.03.05.18 formSetVirtualSer buffer overflow (EUVD-2022-47119)
1 Quelle
Best early October Prime Day deals: Save on TVs, smartwatches, and more tech
1 Quelle
I gave Claude Code $100 and 30 days to make a profit. Day 1, it built a product. Here's the pattern it used.