From 7296bcdc5d6710d73d001f4ff181384d9423f8a8 Mon Sep 17 00:00:00 2001 From: Ryan Jacobchick Date: Wed, 7 Feb 2024 17:58:04 -0500 Subject: [PATCH] Allow CLI version pinning in GHA (#2397) (#2398) * Allow CLI version pinning in GHA (#2397) * prevent segfault in test-community --- action.yml | 9 +++++++-- pkg/engine/engine_test.go | 4 ++++ 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/action.yml b/action.yml index 1bea3a58f..544877ca0 100644 --- a/action.yml +++ b/action.yml @@ -18,6 +18,10 @@ inputs: default: '' description: Extra args to be passed to the trufflehog cli. required: false + version: + default: 'latest' + description: Scan with this trufflehog cli version. + required: false branding: icon: "shield" color: "green" @@ -32,6 +36,7 @@ runs: HEAD: ${{ inputs.head }} ARGS: ${{ inputs.extra_args }} COMMITS: ${{ toJson(github.event.commits) }} + VERSION: ${{ inputs.version }} run: | ########################################## ## ADVANCED USAGE ## @@ -79,9 +84,9 @@ runs: fi ########################################## ## Run TruffleHog ## - ########################################## + ########################################## docker run --rm -v "$REPO_PATH":/tmp -w /tmp \ - ghcr.io/trufflesecurity/trufflehog:latest \ + ghcr.io/trufflesecurity/trufflehog:${VERSION} \ git file:///tmp/ \ --since-commit \ ${BASE:-''} \ diff --git a/pkg/engine/engine_test.go b/pkg/engine/engine_test.go index 39120d18c..49b881a0d 100644 --- a/pkg/engine/engine_test.go +++ b/pkg/engine/engine_test.go @@ -228,6 +228,10 @@ func TestEngine_VersionedDetectorsVerifiedSecrets(t *testing.T) { ctx, cancel := context.WithTimeout(context.Background(), time.Second*10) defer cancel() testSecrets, err := common.GetSecret(ctx, "trufflehog-testing", "detectors4") + if err != nil { + t.Log("Failed to get secrets, likely running community-tests") + return + } assert.NoError(t, err) secretV2 := testSecrets.MustGetField("GITLABV2") secretV1 := testSecrets.MustGetField("GITLAB")