Hashicorp Vault plugin for authenticating Trusted Execution Environments (TEE) like SGX enclaves
Find a file
Harald Hoyer dc80236496
chore(deps): update trufflesecurity/trufflehog action to v3.88.32 (#104)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[trufflesecurity/trufflehog](https://redirect.github.com/trufflesecurity/trufflehog)
| action | patch | `v3.88.15` -> `v3.88.32` |

---

### Release Notes

<details>
<summary>trufflesecurity/trufflehog
(trufflesecurity/trufflehog)</summary>

###
[`v3.88.32`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.32)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.31...v3.88.32)

#### What's Changed

- docs: fix typos by
[@&#8203;bobidle](https://redirect.github.com/bobidle) in
[https://github.com/trufflesecurity/trufflehog/pull/4158](https://redirect.github.com/trufflesecurity/trufflehog/pull/4158)
- Change github file extension log message verbosity by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4159](https://redirect.github.com/trufflesecurity/trufflehog/pull/4159)
- Increase postman logging verbosity by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4160](https://redirect.github.com/trufflesecurity/trufflehog/pull/4160)
- Reduce verbosity of chunk trace logging by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4161](https://redirect.github.com/trufflesecurity/trufflehog/pull/4161)
- Fixed Grafana detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4166](https://redirect.github.com/trufflesecurity/trufflehog/pull/4166)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.31...v3.88.32

###
[`v3.88.31`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.31)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.30...v3.88.31)

#### What's Changed

- \[Fix] Line number issue for custom detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3997](https://redirect.github.com/trufflesecurity/trufflehog/pull/3997)
- Replace anthropic references with groq by
[@&#8203;lihararora](https://redirect.github.com/lihararora) in
[https://github.com/trufflesecurity/trufflehog/pull/4147](https://redirect.github.com/trufflesecurity/trufflehog/pull/4147)
- Updated Github Source Validate method by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4144](https://redirect.github.com/trufflesecurity/trufflehog/pull/4144)
- \[Feat] Added Dropbox API OAuth2 Token Analyzer by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4080](https://redirect.github.com/trufflesecurity/trufflehog/pull/4080)
- Add per-chunk detection logging by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4152](https://redirect.github.com/trufflesecurity/trufflehog/pull/4152)
- chore: run setup-go after checkout by
[@&#8203;Juneezee](https://redirect.github.com/Juneezee) in
[https://github.com/trufflesecurity/trufflehog/pull/4143](https://redirect.github.com/trufflesecurity/trufflehog/pull/4143)
- Fixed Shopify detector line number by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4149](https://redirect.github.com/trufflesecurity/trufflehog/pull/4149)
- Added DataBricks Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4135](https://redirect.github.com/trufflesecurity/trufflehog/pull/4135)
- Add a bunch of Postman logging by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4154](https://redirect.github.com/trufflesecurity/trufflehog/pull/4154)
- Update Twitch detector to handle new RawV2 field by
[@&#8203;amanfcp](https://redirect.github.com/amanfcp) in
[https://github.com/trufflesecurity/trufflehog/pull/4150](https://redirect.github.com/trufflesecurity/trufflehog/pull/4150)

#### New Contributors

- [@&#8203;lihararora](https://redirect.github.com/lihararora) made
their first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4147](https://redirect.github.com/trufflesecurity/trufflehog/pull/4147)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.30...v3.88.31

###
[`v3.88.30`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.30)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.29...v3.88.30)

#### What's Changed

- \[Feat] Detector implementation for Azure Configuration Connection
String Key by [@&#8203;abmussani](https://redirect.github.com/abmussani)
in
[https://github.com/trufflesecurity/trufflehog/pull/3939](https://redirect.github.com/trufflesecurity/trufflehog/pull/3939)
- Improved JDBC Detector Regex by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4109](https://redirect.github.com/trufflesecurity/trufflehog/pull/4109)
- \[Feat] Added Ngrok API Key Analyzer by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4110](https://redirect.github.com/trufflesecurity/trufflehog/pull/4110)
- \[Feat] Added New AccuWeather Detector Version by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4114](https://redirect.github.com/trufflesecurity/trufflehog/pull/4114)
- fix(discordwebhook): Update Discord webhook detector to support
19-digit IDs by
[@&#8203;itsmatinx](https://redirect.github.com/itsmatinx) in
[https://github.com/trufflesecurity/trufflehog/pull/4133](https://redirect.github.com/trufflesecurity/trufflehog/pull/4133)
- Fixed name of netlify analyzer in cli output by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4140](https://redirect.github.com/trufflesecurity/trufflehog/pull/4140)
- \[Feat] Added Mux API Analyzer by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4128](https://redirect.github.com/trufflesecurity/trufflehog/pull/4128)
- \[Feat] Implementation of Posthog Analyzer by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4103](https://redirect.github.com/trufflesecurity/trufflehog/pull/4103)
- Add metrics to the Postman source by
[@&#8203;camgunz](https://redirect.github.com/camgunz) in
[https://github.com/trufflesecurity/trufflehog/pull/4142](https://redirect.github.com/trufflesecurity/trufflehog/pull/4142)
- fix(postman): prevent infinite recursion in variable substitution by
[@&#8203;dustin-decker](https://redirect.github.com/dustin-decker) in
[https://github.com/trufflesecurity/trufflehog/pull/4145](https://redirect.github.com/trufflesecurity/trufflehog/pull/4145)

#### New Contributors

- [@&#8203;itsmatinx](https://redirect.github.com/itsmatinx) made their
first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4133](https://redirect.github.com/trufflesecurity/trufflehog/pull/4133)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.29...v3.88.30

###
[`v3.88.29`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.29)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.28...v3.88.29)

#### What's Changed

- Fixed Kontent Detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4122](https://redirect.github.com/trufflesecurity/trufflehog/pull/4122)
- postman_client.IDNameUUID becomes IdNameUid by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4123](https://redirect.github.com/trufflesecurity/trufflehog/pull/4123)
- Normalize UID to Uid in Postman Code by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4125](https://redirect.github.com/trufflesecurity/trufflehog/pull/4125)
- Postman Code Uses Consistent Casing for Id Var Names by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4124](https://redirect.github.com/trufflesecurity/trufflehog/pull/4124)
- Fastly Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4082](https://redirect.github.com/trufflesecurity/trufflehog/pull/4082)
- \[Feat] Detector implementation for Azure API Management Direct
Management Key by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/3938](https://redirect.github.com/trufflesecurity/trufflehog/pull/3938)
- Monday App Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4120](https://redirect.github.com/trufflesecurity/trufflehog/pull/4120)
- Exclusion of FalsePositive GH's usernames in PrivateKeyDetector by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4046](https://redirect.github.com/trufflesecurity/trufflehog/pull/4046)
- Update PreCommit.md with latest pre-commit stage names by
[@&#8203;BeastImran](https://redirect.github.com/BeastImran) in
[https://github.com/trufflesecurity/trufflehog/pull/4112](https://redirect.github.com/trufflesecurity/trufflehog/pull/4112)
- feat(sources/s3): migrate to AWS SDK v2 by
[@&#8203;Juneezee](https://redirect.github.com/Juneezee) in
[https://github.com/trufflesecurity/trufflehog/pull/4069](https://redirect.github.com/trufflesecurity/trufflehog/pull/4069)
- test(sources/s3): fix missing region error by
[@&#8203;Juneezee](https://redirect.github.com/Juneezee) in
[https://github.com/trufflesecurity/trufflehog/pull/4131](https://redirect.github.com/trufflesecurity/trufflehog/pull/4131)

#### New Contributors

- [@&#8203;BeastImran](https://redirect.github.com/BeastImran) made
their first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4112](https://redirect.github.com/trufflesecurity/trufflehog/pull/4112)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.28...v3.88.29

###
[`v3.88.28`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.28)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.27...v3.88.28)

#### What's Changed

- \[Feat] Added Tunnel Authtoken Verification In Ngrok Detector by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4115](https://redirect.github.com/trufflesecurity/trufflehog/pull/4115)
- Add xAI detector by
[@&#8203;shreyas-sriram](https://redirect.github.com/shreyas-sriram) in
[https://github.com/trufflesecurity/trufflehog/pull/4117](https://redirect.github.com/trufflesecurity/trufflehog/pull/4117)
- Netlify Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4106](https://redirect.github.com/trufflesecurity/trufflehog/pull/4106)
- fix(test/snowflake): Snowflake flaky pattern test by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4083](https://redirect.github.com/trufflesecurity/trufflehog/pull/4083)
- Issue - 3697 - GitHub analyzer panic by
[@&#8203;amanfcp](https://redirect.github.com/amanfcp) in
[https://github.com/trufflesecurity/trufflehog/pull/4113](https://redirect.github.com/trufflesecurity/trufflehog/pull/4113)
- \[Fix] Added Prefix In Dockerhub Detector Regex by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4084](https://redirect.github.com/trufflesecurity/trufflehog/pull/4084)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.27...v3.88.28

###
[`v3.88.27`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.27)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.26...v3.88.27)

#### What's Changed

- Fixed PubnubsubsciptionKey detector verification by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4107](https://redirect.github.com/trufflesecurity/trufflehog/pull/4107)
- chore: added github action custom detector name by
[@&#8203;sahil9001](https://redirect.github.com/sahil9001) in
[https://github.com/trufflesecurity/trufflehog/pull/3417](https://redirect.github.com/trufflesecurity/trufflehog/pull/3417)
- Refactor Netlify Detector by
[@&#8203;amanfcp](https://redirect.github.com/amanfcp) in
[https://github.com/trufflesecurity/trufflehog/pull/4102](https://redirect.github.com/trufflesecurity/trufflehog/pull/4102)
- Update the trufflehog github action description. by
[@&#8203;zricethezav](https://redirect.github.com/zricethezav) in
[https://github.com/trufflesecurity/trufflehog/pull/4108](https://redirect.github.com/trufflesecurity/trufflehog/pull/4108)
- Make a first pass at some structural introduction docs by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4076](https://redirect.github.com/trufflesecurity/trufflehog/pull/4076)
- Improve pre-commit hooks documentation by
[@&#8203;dustin-decker](https://redirect.github.com/dustin-decker) in
[https://github.com/trufflesecurity/trufflehog/pull/4098](https://redirect.github.com/trufflesecurity/trufflehog/pull/4098)
- feat: bing subscription key support by
[@&#8203;snieguu](https://redirect.github.com/snieguu) in
[https://github.com/trufflesecurity/trufflehog/pull/4092](https://redirect.github.com/trufflesecurity/trufflehog/pull/4092)
- Postman increase http client timeout by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/4086](https://redirect.github.com/trufflesecurity/trufflehog/pull/4086)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.26...v3.88.27

###
[`v3.88.26`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.26)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.25...v3.88.26)

#### What's Changed

- fix(deps): update module github.com/couchbase/gocb/v2 to v2.10.0 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4075](https://redirect.github.com/trufflesecurity/trufflehog/pull/4075)
- Polish logging around git and archives to reduce noise by
[@&#8203;camgunz](https://redirect.github.com/camgunz) in
[https://github.com/trufflesecurity/trufflehog/pull/4034](https://redirect.github.com/trufflesecurity/trufflehog/pull/4034)
- \[Feat] Support Dockerhub OATs by
[@&#8203;harmonherring-pro](https://redirect.github.com/harmonherring-pro)
in
[https://github.com/trufflesecurity/trufflehog/pull/4062](https://redirect.github.com/trufflesecurity/trufflehog/pull/4062)
- \[Fix] Updated Dropbox Detector by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4073](https://redirect.github.com/trufflesecurity/trufflehog/pull/4073)
- (Fix) Exclude trailing quotes and commas in Password by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4078](https://redirect.github.com/trufflesecurity/trufflehog/pull/4078)
- Added azure COSMOSDB detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3951](https://redirect.github.com/trufflesecurity/trufflehog/pull/3951)
- Ignore common key by
[@&#8203;dylanTruffle](https://redirect.github.com/dylanTruffle) in
[https://github.com/trufflesecurity/trufflehog/pull/4039](https://redirect.github.com/trufflesecurity/trufflehog/pull/4039)
- test(sources/s3): fix infinite blocking and timeout issue in
TestSource_Chunks by
[@&#8203;Juneezee](https://redirect.github.com/Juneezee) in
[https://github.com/trufflesecurity/trufflehog/pull/4048](https://redirect.github.com/trufflesecurity/trufflehog/pull/4048)
- Small comment fix: workspaces --> collections by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4093](https://redirect.github.com/trufflesecurity/trufflehog/pull/4093)
- Netlify Detector Version 2 implementation by
[@&#8203;amanfcp](https://redirect.github.com/amanfcp) in
[https://github.com/trufflesecurity/trufflehog/pull/4091](https://redirect.github.com/trufflesecurity/trufflehog/pull/4091)
- Harness Detector Implementation by
[@&#8203;amanfcp](https://redirect.github.com/amanfcp) in
[https://github.com/trufflesecurity/trufflehog/pull/4085](https://redirect.github.com/trufflesecurity/trufflehog/pull/4085)
- \[Fix] Added Shannon Entropy Check In AccuWeather Detector by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4096](https://redirect.github.com/trufflesecurity/trufflehog/pull/4096)
- fix(deps): update module github.com/snowflakedb/gosnowflake to v1.13.3
\[security] by [@&#8203;renovate](https://redirect.github.com/renovate)
in
[https://github.com/trufflesecurity/trufflehog/pull/4105](https://redirect.github.com/trufflesecurity/trufflehog/pull/4105)
- feat: langfuse support by
[@&#8203;snieguu](https://redirect.github.com/snieguu) in
[https://github.com/trufflesecurity/trufflehog/pull/4079](https://redirect.github.com/trufflesecurity/trufflehog/pull/4079)
- Remove unnecessary verbosity call when logging error by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4097](https://redirect.github.com/trufflesecurity/trufflehog/pull/4097)
- Don't die on workspace request failure to Postman API by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4095](https://redirect.github.com/trufflesecurity/trufflehog/pull/4095)
- Don't die on collection request failure to Postman API by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4094](https://redirect.github.com/trufflesecurity/trufflehog/pull/4094)
- Add --no-color option to force disabling colorized output by
[@&#8203;TheToddLuci0](https://redirect.github.com/TheToddLuci0) in
[https://github.com/trufflesecurity/trufflehog/pull/4081](https://redirect.github.com/trufflesecurity/trufflehog/pull/4081)

#### New Contributors

- [@&#8203;amanfcp](https://redirect.github.com/amanfcp) made their
first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4091](https://redirect.github.com/trufflesecurity/trufflehog/pull/4091)
- [@&#8203;snieguu](https://redirect.github.com/snieguu) made their
first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4079](https://redirect.github.com/trufflesecurity/trufflehog/pull/4079)
- [@&#8203;TheToddLuci0](https://redirect.github.com/TheToddLuci0) made
their first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4081](https://redirect.github.com/trufflesecurity/trufflehog/pull/4081)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.25...v3.88.26

###
[`v3.88.25`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.25)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.24...v3.88.25)

#### What's Changed

- fix(deps): update module golang.org/x/net to v0.38.0 \[security] by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4064](https://redirect.github.com/trufflesecurity/trufflehog/pull/4064)
- Improved Baremetrics detector regex pattern by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4060](https://redirect.github.com/trufflesecurity/trufflehog/pull/4060)
- (fix) Indeterminate verification issue in Clickup detector by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4047](https://redirect.github.com/trufflesecurity/trufflehog/pull/4047)
- \[Fix] Updated DigitalOceanV2 Detector by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4050](https://redirect.github.com/trufflesecurity/trufflehog/pull/4050)
- \[Fix] Updated DigitalOcean Token Detector by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4052](https://redirect.github.com/trufflesecurity/trufflehog/pull/4052)
- \[Fix] Fixed Okta Detector Integration Test Case input by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4053](https://redirect.github.com/trufflesecurity/trufflehog/pull/4053)
- Added support for indeterminate verification for letter `B` detectors
by [@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771)
in
[https://github.com/trufflesecurity/trufflehog/pull/4049](https://redirect.github.com/trufflesecurity/trufflehog/pull/4049)
- Create Docker registry auth detector by
[@&#8203;rgmz](https://redirect.github.com/rgmz) in
[https://github.com/trufflesecurity/trufflehog/pull/2677](https://redirect.github.com/trufflesecurity/trufflehog/pull/2677)
- \[Fix] Added Indeterminate Verification In First 24 Detectors Starting
With the Letter "A" by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4061](https://redirect.github.com/trufflesecurity/trufflehog/pull/4061)
- Adding new canary account by
[@&#8203;dylanTruffle](https://redirect.github.com/dylanTruffle) in
[https://github.com/trufflesecurity/trufflehog/pull/4070](https://redirect.github.com/trufflesecurity/trufflehog/pull/4070)
- fixed authOmanagement detector integration test failure by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4013](https://redirect.github.com/trufflesecurity/trufflehog/pull/4013)
- fix(deps): update module cloud.google.com/go/secretmanager to v1.14.7
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4065](https://redirect.github.com/trufflesecurity/trufflehog/pull/4065)
- fix(deps): update module github.com/go-ldap/ldap/v3 to v3.4.11 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4066](https://redirect.github.com/trufflesecurity/trufflehog/pull/4066)
- \[Fix] Fix Abyssale Detector Typo by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4067](https://redirect.github.com/trufflesecurity/trufflehog/pull/4067)
- Stop logging chunks by
[@&#8203;rosecodym](https://redirect.github.com/rosecodym) in
[https://github.com/trufflesecurity/trufflehog/pull/4056](https://redirect.github.com/trufflesecurity/trufflehog/pull/4056)
- fix(deps): update module github.com/gabriel-vasile/mimetype to v1.4.9
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4071](https://redirect.github.com/trufflesecurity/trufflehog/pull/4071)
- fix(deps): update module github.com/xo/dburl to v0.23.7 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4072](https://redirect.github.com/trufflesecurity/trufflehog/pull/4072)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.24...v3.88.25

###
[`v3.88.24`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.24)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.23...v3.88.24)

#### What's Changed

- fix(deps): update module github.com/xanzy/go-gitlab to v0.115.0 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/3755](https://redirect.github.com/trufflesecurity/trufflehog/pull/3755)
- fix(deps): update aws-sdk-go-v2 monorepo by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4011](https://redirect.github.com/trufflesecurity/trufflehog/pull/4011)
- editing jenkins source to encode URLs by
[@&#8203;jordanTunstill](https://redirect.github.com/jordanTunstill) in
[https://github.com/trufflesecurity/trufflehog/pull/4006](https://redirect.github.com/trufflesecurity/trufflehog/pull/4006)
- \[Fix] - Migrated github.com/xanzy/go-gitlab to
gitlab.com/gitlab-org/api/client-go by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4014](https://redirect.github.com/trufflesecurity/trufflehog/pull/4014)
- fix(deps): update github.com/avast/apkparser digest to
[`e2100ee`](e2100ee)
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/3965](https://redirect.github.com/trufflesecurity/trufflehog/pull/3965)
- fix(deps): update module github.com/xo/dburl to v0.23.6 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4016](https://redirect.github.com/trufflesecurity/trufflehog/pull/4016)
- fix(deps): update github.com/lrstanley/bubblezone digest to
[`e13639e`](e13639e)
- autoclosed by [@&#8203;renovate](https://redirect.github.com/renovate)
in
[https://github.com/trufflesecurity/trufflehog/pull/4003](https://redirect.github.com/trufflesecurity/trufflehog/pull/4003)
- fix(deps): update module cloud.google.com/go/secretmanager to v1.14.6
by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4012](https://redirect.github.com/trufflesecurity/trufflehog/pull/4012)
- Reverted cloud.google.com/go/secretmanager to v1.14.2 by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4022](https://redirect.github.com/trufflesecurity/trufflehog/pull/4022)
- chore(deps): update sigstore/cosign-installer action to v3.8.1 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4021](https://redirect.github.com/trufflesecurity/trufflehog/pull/4021)
- fix(deps): update module github.com/brianvoe/gofakeit/v7 to v7.2.1 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4026](https://redirect.github.com/trufflesecurity/trufflehog/pull/4026)
- fix(deps): update module go.uber.org/mock to v0.5.1 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4019](https://redirect.github.com/trufflesecurity/trufflehog/pull/4019)
- fix(deps): update module github.com/envoyproxy/protoc-gen-validate to
v1.2.1 by [@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4028](https://redirect.github.com/trufflesecurity/trufflehog/pull/4028)
- Include complete gcp key for analysis by
[@&#8203;bill-rich](https://redirect.github.com/bill-rich) in
[https://github.com/trufflesecurity/trufflehog/pull/4029](https://redirect.github.com/trufflesecurity/trufflehog/pull/4029)
- (fix) domain regex issue in JiraToken detector by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4005](https://redirect.github.com/trufflesecurity/trufflehog/pull/4005)
- Bitly Detector - Added support for indeterminate verification by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4031](https://redirect.github.com/trufflesecurity/trufflehog/pull/4031)
- Updated ConvertAPI Detector Pattern & Endpoint by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4017](https://redirect.github.com/trufflesecurity/trufflehog/pull/4017)
- Better Test Output For Git Diff Parsing by
[@&#8203;martinlocklear](https://redirect.github.com/martinlocklear) in
[https://github.com/trufflesecurity/trufflehog/pull/4018](https://redirect.github.com/trufflesecurity/trufflehog/pull/4018)
- \[Fix] AWS User Agent issue by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/4032](https://redirect.github.com/trufflesecurity/trufflehog/pull/4032)
- updated go.mod by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4033](https://redirect.github.com/trufflesecurity/trufflehog/pull/4033)
- fix(deps): update module github.com/getsentry/sentry-go to v0.32.0 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4030](https://redirect.github.com/trufflesecurity/trufflehog/pull/4030)
- \[Feat] Plaid API Analyzer by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4004](https://redirect.github.com/trufflesecurity/trufflehog/pull/4004)
- fix(deps): update module github.com/aws/smithy-go to v1.22.3 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4038](https://redirect.github.com/trufflesecurity/trufflehog/pull/4038)
- fix(deps): update aws-sdk-go-v2 monorepo by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/4037](https://redirect.github.com/trufflesecurity/trufflehog/pull/4037)
- Allow filesystem exclusion to eagerly prune the enumerated tree by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4008](https://redirect.github.com/trufflesecurity/trufflehog/pull/4008)
- \[feat] Addition of Detector - Azure Subsciprtion Keys by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/3998](https://redirect.github.com/trufflesecurity/trufflehog/pull/3998)
- Okta Detector - Added Check for Indeterminate Verification Results by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/4045](https://redirect.github.com/trufflesecurity/trufflehog/pull/4045)
- Improved Besttime detector regex pattern by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/4059](https://redirect.github.com/trufflesecurity/trufflehog/pull/4059)

#### New Contributors

- [@&#8203;martinlocklear](https://redirect.github.com/martinlocklear)
made their first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/4018](https://redirect.github.com/trufflesecurity/trufflehog/pull/4018)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.23...v3.88.24

###
[`v3.88.23`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.23)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.22...v3.88.23)

#### What's Changed

- Make verification cache detector type-aware by
[@&#8203;rosecodym](https://redirect.github.com/rosecodym) in
[https://github.com/trufflesecurity/trufflehog/pull/4009](https://redirect.github.com/trufflesecurity/trufflehog/pull/4009)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.22...v3.88.23

###
[`v3.88.22`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.22)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.21...v3.88.22)

#### What's Changed

- Added logging for Postman API response headers by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/4007](https://redirect.github.com/trufflesecurity/trufflehog/pull/4007)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.21...v3.88.22

###
[`v3.88.21`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.21)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.20...v3.88.21)

#### What's Changed

- Added a rate limiter for getting the overall list of Postman
workspaces by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/4002](https://redirect.github.com/trufflesecurity/trufflehog/pull/4002)
- chore(deps): update dependency go by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/3958](https://redirect.github.com/trufflesecurity/trufflehog/pull/3958)
- \[Feat] Added Figma (PAT) Analyzer by
[@&#8203;nabeelalam](https://redirect.github.com/nabeelalam) in
[https://github.com/trufflesecurity/trufflehog/pull/3974](https://redirect.github.com/trufflesecurity/trufflehog/pull/3974)
- \[Feat] Detector implementation for Azure API Management Repository
key by [@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/3955](https://redirect.github.com/trufflesecurity/trufflehog/pull/3955)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.20...v3.88.21

###
[`v3.88.20`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.20)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.19...v3.88.20)

#### What's Changed

- Postman source handle different JSON info for headers by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/3995](https://redirect.github.com/trufflesecurity/trufflehog/pull/3995)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.19...v3.88.20

###
[`v3.88.19`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.19)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.18...v3.88.19)

#### What's Changed

- updated storyblok detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3981](https://redirect.github.com/trufflesecurity/trufflehog/pull/3981)
- Update sentry endpoint by
[@&#8203;zricethezav](https://redirect.github.com/zricethezav) in
[https://github.com/trufflesecurity/trufflehog/pull/3983](https://redirect.github.com/trufflesecurity/trufflehog/pull/3983)
- added sentry org token detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3985](https://redirect.github.com/trufflesecurity/trufflehog/pull/3985)
- Optimized twitch detectors by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3987](https://redirect.github.com/trufflesecurity/trufflehog/pull/3987)
- (fix) Preserve Newline Characters in Multi-line PrivateKeys in
Analyzer by [@&#8203;abmussani](https://redirect.github.com/abmussani)
in
[https://github.com/trufflesecurity/trufflehog/pull/3988](https://redirect.github.com/trufflesecurity/trufflehog/pull/3988)
- optimized ipquality detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3971](https://redirect.github.com/trufflesecurity/trufflehog/pull/3971)
- \[Feat] Detector implementation for Azure SAS Tokens by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/3963](https://redirect.github.com/trufflesecurity/trufflehog/pull/3963)
- Add tenant_id to MS Teams source proto definition by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/3986](https://redirect.github.com/trufflesecurity/trufflehog/pull/3986)
- fix(deps): update module github.com/golang-jwt/jwt/v5 to v5.2.2
\[security] by [@&#8203;renovate](https://redirect.github.com/renovate)
in
[https://github.com/trufflesecurity/trufflehog/pull/3992](https://redirect.github.com/trufflesecurity/trufflehog/pull/3992)
- removed vebiage saying we don't trigger aws canary tokens, as we do.
by [@&#8203;jordanTunstill](https://redirect.github.com/jordanTunstill)
in
[https://github.com/trufflesecurity/trufflehog/pull/3991](https://redirect.github.com/trufflesecurity/trufflehog/pull/3991)
- fixed and improved squareapp detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3993](https://redirect.github.com/trufflesecurity/trufflehog/pull/3993)
- \[FIX] added tags for integration test of ipquality detector by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3996](https://redirect.github.com/trufflesecurity/trufflehog/pull/3996)
- (fix) Remove `db_type` parameter Postgres detector during making
connection by [@&#8203;abmussani](https://redirect.github.com/abmussani)
in
[https://github.com/trufflesecurity/trufflehog/pull/3989](https://redirect.github.com/trufflesecurity/trufflehog/pull/3989)
- removal of blog and aws canary not triggered verbiage. by
[@&#8203;jordanTunstill](https://redirect.github.com/jordanTunstill) in
[https://github.com/trufflesecurity/trufflehog/pull/3990](https://redirect.github.com/trufflesecurity/trufflehog/pull/3990)
- Add option to bypass Bitbucket installation type autodetection by
[@&#8203;rosecodym](https://redirect.github.com/rosecodym) in
[https://github.com/trufflesecurity/trufflehog/pull/3999](https://redirect.github.com/trufflesecurity/trufflehog/pull/3999)

#### New Contributors

- [@&#8203;jordanTunstill](https://redirect.github.com/jordanTunstill)
made their first contribution in
[https://github.com/trufflesecurity/trufflehog/pull/3991](https://redirect.github.com/trufflesecurity/trufflehog/pull/3991)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.18...v3.88.19

###
[`v3.88.18`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.18)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.17...v3.88.18)

#### What's Changed

- Update results help text by
[@&#8203;rosecodym](https://redirect.github.com/rosecodym) in
[https://github.com/trufflesecurity/trufflehog/pull/3978](https://redirect.github.com/trufflesecurity/trufflehog/pull/3978)
- \[fix] - Sonarcloud detector by
[@&#8203;kagahd](https://redirect.github.com/kagahd) in
[https://github.com/trufflesecurity/trufflehog/pull/3982](https://redirect.github.com/trufflesecurity/trufflehog/pull/3982)

#### New Contributors

- [@&#8203;kagahd](https://redirect.github.com/kagahd) made their first
contribution in
[https://github.com/trufflesecurity/trufflehog/pull/3982](https://redirect.github.com/trufflesecurity/trufflehog/pull/3982)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.17...v3.88.18

###
[`v3.88.17`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.17)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.16...v3.88.17)

#### What's Changed

- Updated anthropic detector to detect admin keys by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3969](https://redirect.github.com/trufflesecurity/trufflehog/pull/3969)
- \[Fix] Upgraded AWS go-sdk to V2 (only for AWS Canary Token
Verification) by
[@&#8203;abmussani](https://redirect.github.com/abmussani) in
[https://github.com/trufflesecurity/trufflehog/pull/3907](https://redirect.github.com/trufflesecurity/trufflehog/pull/3907)
- updated anthropic analyzer to analyze admin keys by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3973](https://redirect.github.com/trufflesecurity/trufflehog/pull/3973)
- fix(deps): update module golang.org/x/net to v0.36.0 \[security] by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/3975](https://redirect.github.com/trufflesecurity/trufflehog/pull/3975)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.16...v3.88.17

###
[`v3.88.16`](https://redirect.github.com/trufflesecurity/trufflehog/releases/tag/v3.88.16)

[Compare
Source](https://redirect.github.com/trufflesecurity/trufflehog/compare/v3.88.15...v3.88.16)

#### What's Changed

- Add terminal output for analyze if the detector support it by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3959](https://redirect.github.com/trufflesecurity/trufflehog/pull/3959)
- Postman enumeration rate limiting by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/3957](https://redirect.github.com/trufflesecurity/trufflehog/pull/3957)
- Groq Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3962](https://redirect.github.com/trufflesecurity/trufflehog/pull/3962)
- Implement rate limiters for every Postman client function that uses a
GET request by
[@&#8203;casey-tran](https://redirect.github.com/casey-tran) in
[https://github.com/trufflesecurity/trufflehog/pull/3964](https://redirect.github.com/trufflesecurity/trufflehog/pull/3964)
- fix(deps): update module github.com/jedib0t/go-pretty/v6 to v6.6.7 by
[@&#8203;renovate](https://redirect.github.com/renovate) in
[https://github.com/trufflesecurity/trufflehog/pull/3960](https://redirect.github.com/trufflesecurity/trufflehog/pull/3960)
- TUI - handle relative paths by
[@&#8203;hxnyk](https://redirect.github.com/hxnyk) in
[https://github.com/trufflesecurity/trufflehog/pull/3967](https://redirect.github.com/trufflesecurity/trufflehog/pull/3967)
- \[bug] - Avoid panic in Snowflake detector by
[@&#8203;ahrav](https://redirect.github.com/ahrav) in
[https://github.com/trufflesecurity/trufflehog/pull/3966](https://redirect.github.com/trufflesecurity/trufflehog/pull/3966)
- LaunchDarkly Token Analyzer by
[@&#8203;kashifkhan0771](https://redirect.github.com/kashifkhan0771) in
[https://github.com/trufflesecurity/trufflehog/pull/3948](https://redirect.github.com/trufflesecurity/trufflehog/pull/3948)

**Full Changelog**:
https://github.com/trufflesecurity/trufflehog/compare/v3.88.15...v3.88.16

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/matter-labs/vault-auth-tee).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4xODUuNCIsInVwZGF0ZWRJblZlciI6IjQwLjE2LjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
2025-05-22 09:01:44 +02:00
.github chore(deps): update trufflesecurity/trufflehog action to v3.88.32 2025-05-21 23:17:26 +00:00
cmd/vault-auth-tee feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
packages chore: Update nix workflow and flake.lock 2024-07-01 12:58:24 +02:00
test-fixtures/keys feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
.gitignore feat: initial commit 2023-10-26 14:15:52 +02:00
backend.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
backend_test.go all: use errors.New() which has no param instead of fmt.Errorf() 2024-03-10 09:03:53 +08:00
CONTRIBUTING.md feat: initial commit 2023-10-26 14:15:52 +02:00
Dockerfile feat: build the container image with nix 2024-02-13 13:21:23 +01:00
flake.lock chore: Update nix workflow and flake.lock 2024-07-01 12:58:24 +02:00
flake.nix chore: Update nix workflow and flake.lock 2024-07-01 12:58:24 +02:00
go.mod chore(deps): update 2024-06-10 10:32:19 +02:00
go.sum chore(deps): update 2024-06-10 10:32:19 +02:00
LICENSE feat: initial commit 2023-10-26 14:15:52 +02:00
path_info.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
path_login.go all: use errors.New() which has no param instead of fmt.Errorf() 2024-03-10 09:03:53 +08:00
path_login_test.go feat: get current unix time for verification with NTS 2024-02-13 10:26:45 +01:00
path_tees.go fix: enable clearing the sgx_mrsigner and sgx_mrenclave field 2024-02-27 11:58:55 +01:00
README.md docs: lower warning in README.md 2024-03-26 16:04:02 +01:00
renovate.json feat: initial commit 2023-10-26 14:15:52 +02:00
roughntstime.go all: use errors.New() which has no param instead of fmt.Errorf() 2024-03-10 09:03:53 +08:00
SECURITY.md feat: initial commit 2023-10-26 14:15:52 +02:00
sgxquote.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
sgxquote_test.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
test_responder.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00
version.go feat: restructure project and fix vault/sdk version 2024-02-12 17:12:24 +01:00

vault-auth-tee

TEE remote attestation plugin for Hashicorp Vault

Disclaimer

This plugin has not yet received an audit. Use at your own risk.

License

All of the code is licensed under the Mozilla Public License 2.0 unless otherwise specified. Most of the vault plugin code is based on the vault builtin/credential/cert plugin.

Build Setup

$ wget -qO - https://download.01.org/intel-sgx/sgx_repo/ubuntu/intel-sgx-deb.key | sudo apt-key add -
$ sudo bash -c 'echo "deb [arch=amd64] https://download.01.org/intel-sgx/sgx_repo/ubuntu focal main" > /etc/apt/sources.list.d/intel-sgx.list'
$ sudo apt update
$ sudo apt install -y --no-install-recommends \
    libsgx-headers \
    libsgx-enclave-common \
    libsgx-urts \
    libsgx-dcap-quote-verify \
    libsgx-dcap-quote-verify-dev

Configuration

Create or Update via the ${plugin}/tees/$name endpoint

{
    "name": "TEE_role_name",
    "token_policies": "policy1,policy2,...",
    "types": "sgx",
    "sgx_mrsigner": "298037d88782e022e019b3020745b78aa40ed95c77da4bf7f3253d3a44c4fd7e",
    "sgx_mrenclave": "18946b3547d3ca036f4df7b516857e28fd512d69fed3411dc660537912faabf8",
    "sgx_isv_prodid": 0,
    "sgx_min_isv_svn": 0,
    "sgx_allowed_tcb_levels": "Ok,ConfigNeeded,OutOfDate,OutOfDateConfigNeeded,SwHardeningNeeded,ConfigAndSwHardeningNeeded"
}
  • At least one of sgx_mrsigner or sgx_mrenclave must be set. If both are set, both are used for matching.
  • sgx_isv_prodid is optional and defaults to 0.
  • sgx_min_isv_svn is optional and defaults to 0.
  • sgx_allowed_tcb_levels is optional and defaults to Ok.

Authentication

  • Client TEE generates a self-signed TLS client certificate
  • Client TEE generates an attestation report, which includes the hash of the public key of the client certificate (in case of SGX, a sha256 sum of the public key)
  • Client TEE fetches all collateral material via e.g. Intel DCAP (tee_qv_get_collateral)
  • Client TEE sends POST request with a TLS connection using the client certificate to Vault via the ${plugin}/login endpoint with the name, attestation report and the attestation collateral material
  • An optional challenge can be included in the POST request, which is then included in the attestation report of the vault response
{
    "name": "The name of the TEE role to authenticate against.",
    "quote": "The quote Base64 encoded.",
    "collateral": "The collateral Json string encoded.",
    "challenge": "An optional challenge hex encoded."
}

The response contains the Vault token and, if a challenge was included, the vault attestation report, which must contain the challenge bytes in the report_data of the quote.

{
    "auth": {
        "client_token": "The Vault token.",
        "....": "...."
    },
    "data": {
        "quote": "The vault quote Base64 encoded.",
        "collateral": "The vault collateral Json string encoded."
    }
}

Collateral Json encoding

See sgx_ql_lib_common.h

{
    "major_version": uint16,
    "minor_version": uint16,
    "tee_type": uint32,
    "pck_crl_issuer_chain": []byte,
    "root_ca_crl": []byte,
    "pck_crl": []byte,
    "tcb_info_issuer_chain": []byte,
    "tcb_info": []byte,
    "qe_identity_issuer_chain": []byte,
    "qe_identity": []byte
}