From f845f184e44d45a8f5aa189a85bad263cbb18d60 Mon Sep 17 00:00:00 2001 From: Rush <12215946+eightseventhreethree@users.noreply.github.com> Date: Wed, 8 Jul 2026 02:57:06 -0400 Subject: [PATCH] feat(action): add image input to allow registry mirror overrides (#4965) * feat(action): add image input to allow registry mirror overrides * quote variables to prevent shell injection risk --------- Co-authored-by: Kashif Khan <70996046+kashifkhan0771@users.noreply.github.com> Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com> --- README.md | 4 ++++ action.yml | 7 ++++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index e01637d14..3f08eb1d9 100644 --- a/README.md +++ b/README.md @@ -711,6 +711,10 @@ TruffleHog statically detects [https://canarytokens.org/](https://canarytokens.o head: # optional # Extra args to be passed to the trufflehog cli. extra_args: --log-level=2 --results=verified,unknown + # Scan with a specific TruffleHog version (default: latest). + version: + # Docker image to pull. Override to use a registry mirror (default: ghcr.io/trufflesecurity/trufflehog). + image: ``` If you'd like to specify specific `base` and `head` refs, you can use the `base` argument (`--since-commit` flag in TruffleHog CLI) and the `head` argument (`--branch` flag in the TruffleHog CLI). We only recommend using these arguments for very specific use cases, where the default behavior does not work. diff --git a/action.yml b/action.yml index 2acb0ad23..1e2af3fbb 100644 --- a/action.yml +++ b/action.yml @@ -22,6 +22,10 @@ inputs: default: "latest" description: Scan with this trufflehog cli version. required: false + image: + default: "ghcr.io/trufflesecurity/trufflehog" + description: Docker image to use. Override to point at a registry mirror. + required: false branding: icon: "shield" color: "green" @@ -37,6 +41,7 @@ runs: ARGS: ${{ inputs.extra_args }} COMMIT_IDS: ${{ toJson(github.event.commits.*.id) }} VERSION: ${{ inputs.version }} + IMAGE: ${{ inputs.image }} run: | ########################################## ## ADVANCED USAGE ## @@ -94,7 +99,7 @@ runs: ## Run TruffleHog ## ########################################## docker run --rm -v .:/tmp -w /tmp \ - ghcr.io/trufflesecurity/trufflehog:${VERSION} \ + "${IMAGE}:${VERSION}" \ git file:///tmp/ \ --since-commit \ ${BASE:-''} \