Secrets detection should not skip *.pyc #7170
Closed
fproulx-boostsecurity
started this conversation in
Ideas
Replies: 1 comment 2 replies
-
Thanks for sharing. It makes a lot of sense. The We'll play with |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
As demonstrated in this incident report https://blog.pypi.org/posts/2024-07-08-incident-report-leaked-admin-personal-access-token/ . Secrets in Docker images could very well be part of
*.pyc
. At the moment, Trivy's secret detection appears to skip / ignore those files (trivy/pkg/fanal/analyzer/secret/secret.go
Line 57 in 2a577a7
Target
Container Image
Scanner
Secret
Beta Was this translation helpful? Give feedback.
All reactions