Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix: trufflehog --only-verified (#286)
Recently multiple false positives reported for trufflehog v3: https://splunk.slack.com/archives/CRTNPEZ4M/p1717405810934429 Let's add --only-verified flag to callout to avoid multiple fp for now. Final solution need to be established/reviewed with prodsec. More info on secrets verification in trufflehog: https://trufflesecurity.com/blog/how-trufflehog-verifies-secrets Tests: https://github.com/splunk/splunk-add-on-for-microsoft-office-365/actions/runs/9399856169
- Loading branch information