Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package trufflehog for openSUSE:Factory checked in at 2026-07-28 17:54:38 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/trufflehog (Old) and /work/SRC/openSUSE:Factory/.trufflehog.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "trufflehog" Tue Jul 28 17:54:38 2026 rev:129 rq:1367865 version:3.96.0 Changes: -------- --- /work/SRC/openSUSE:Factory/trufflehog/trufflehog.changes 2026-07-14 13:49:29.718083345 +0200 +++ /work/SRC/openSUSE:Factory/.trufflehog.new.2004/trufflehog.changes 2026-07-28 17:56:49.318191334 +0200 @@ -1,0 +2,25 @@ +Mon Jul 27 04:58:05 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 3.96.0: + * fix(handlers): apk handler now doesnt check for apk extension since json-enumerator and other byte stream methods wouldnt have it (#5151) + * fix(detectors/posthog): widen phx_ key body to {43,48} (#5133) + * [chore] Change job_id in metric to source_type (#5149) + * updated detector to include underscore char (#5121) + * Fix `scan_all_installations` Rejecting Org Member Personal Repos (#5142) + * Retry git clone on transient network errors (#5132) + * Update module github.com/go-git/go-git/v5 to v5.19.1 [SECURITY] (#5034) + * document Config.SourceManager (#5002) + * Log analyze errors for HuggingFace analyzer (#5130) + * Log analyze errors for Postgres analyzer (#5131) + * [INS-255] Updated datadog detector to set verificationError in case of a verification error (#4661) + * [Feature] Added SonarQube Cloud "Scoped Organization Token" Detector (#4739) + * [INS-312] Duo API Secret Key Detector (#4771) + * Update Cloudflare detectors for 2026+ prefixed credential formats (include upstream PR changes) (#5111) + * Add metrics for chunks and results (#5128) + * Log analyze errors for Anthropic Analyzer (#5120) + * Fix GitLab project metadata cache and switch to LRU (#4727) + * [INT-718] Add TargetNotFoundError for targeted scan targets missing from the source (#5123) + * fix(jiratoken/v1): only verify when the response body contains the authenticated user (#5122) + * [INS-355] Added Hashicorp vault token detector (#4819) + +------------------------------------------------------------------- Old: ---- trufflehog-3.95.9.obscpio New: ---- trufflehog-3.96.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ trufflehog.spec ++++++ --- /var/tmp/diff_new_pack.MD55xy/_old 2026-07-28 17:56:53.382333460 +0200 +++ /var/tmp/diff_new_pack.MD55xy/_new 2026-07-28 17:56:53.386333599 +0200 @@ -17,14 +17,14 @@ Name: trufflehog -Version: 3.95.9 +Version: 3.96.0 Release: 0 Summary: CLI tool to find exposed secrets in source and archives License: AGPL-3.0-or-later AND MPL-2.0 AND LGPL-3.0-or-later URL: https://github.com/trufflesecurity/trufflehog Source: trufflehog-%{version}.tar.gz Source1: vendor.tar.gz -BuildRequires: golang(API) >= 1.24 +BuildRequires: golang(API) >= 1.25 %description TruffleHog is a scanning engine that helps find exposed secrets ++++++ _service ++++++ --- /var/tmp/diff_new_pack.MD55xy/_old 2026-07-28 17:56:53.426334998 +0200 +++ /var/tmp/diff_new_pack.MD55xy/_new 2026-07-28 17:56:53.430335138 +0200 @@ -2,7 +2,7 @@ <service name="obs_scm" mode="manual"> <param name="url">https://github.com/trufflesecurity/trufflehog.git</param> <param name="scm">git</param> - <param name="revision">refs/tags/v3.95.9</param> + <param name="revision">refs/tags/v3.96.0</param> <param name="match-tag">v*</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.MD55xy/_old 2026-07-28 17:56:53.474336677 +0200 +++ /var/tmp/diff_new_pack.MD55xy/_new 2026-07-28 17:56:53.478336816 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/trufflesecurity/trufflehog.git</param> - <param name="changesrevision">27b0417c16317ca9a472a9a8092acce143b49c55</param></service></servicedata> + <param name="changesrevision">6f3c981e7b77f235fd2702dd74af25fc4b72bf11</param></service></servicedata> (No newline at EOF) ++++++ trufflehog-3.95.9.obscpio -> trufflehog-3.96.0.obscpio ++++++ ++++ 8888 lines of diff (skipped) ++++++ trufflehog.obsinfo ++++++ --- /var/tmp/diff_new_pack.MD55xy/_old 2026-07-28 17:57:00.074567490 +0200 +++ /var/tmp/diff_new_pack.MD55xy/_new 2026-07-28 17:57:00.130569448 +0200 @@ -1,5 +1,5 @@ name: trufflehog -version: 3.95.9 -mtime: 1783628891 -commit: 27b0417c16317ca9a472a9a8092acce143b49c55 +version: 3.96.0 +mtime: 1784914726 +commit: 6f3c981e7b77f235fd2702dd74af25fc4b72bf11 ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/trufflehog/vendor.tar.gz /work/SRC/openSUSE:Factory/.trufflehog.new.2004/vendor.tar.gz differ: char 40, line 1
