5 ms·
you should include seed phrase and private key detection. a few crypto protocols that offer public docker images have been drained from accidentally committing
by nubb 3y ago
you should include seed phrase and private key detection. a few crypto protocols that offer public docker images have been drained from accidentally committing keys to docker hub.
- 8organicbits 3y agoI think Trivy does that already [1]. I personally use trufflehog [2] to find secrets of all kinds. Unfortunately, these sorts of tools have false positives [1] https://aquasecurity.github.io/trivy/v0.27.1/docs/secret/scanning/ https://aquasecurity.github.io/trivy/v0.27.1/docs/secret/sca... [2] https://github.com/trufflesecurity/trufflehog https://github.com/trufflesecurity/trufflehog