Commit 0e9c5ba
authored
fix: trufflehog --only-verified (#286)
Recently multiple false positives reported for trufflehog v3:
https://splunk.slack.com/archives/CRTNPEZ4M/p1717405810934429
Let's add --only-verified flag to callout to avoid multiple fp for now.
Final solution need to be established/reviewed with prodsec.
More info on secrets verification in trufflehog:
https://trufflesecurity.com/blog/how-trufflehog-verifies-secrets
Tests:
https://github.com/splunk/splunk-add-on-for-microsoft-office-365/actions/runs/93998561691 parent 2833a37 commit 0e9c5ba
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
267 | 267 | | |
268 | 268 | | |
269 | 269 | | |
270 | | - | |
| 270 | + | |
271 | 271 | | |
272 | 272 | | |
273 | 273 | | |
| |||
0 commit comments