aquasecurity/trivy

fix: scan `.git/config` for secrets

Open

#6,699 创建于 2024年5月16日

在 GitHub 查看
 (2 评论) (5 反应) (1 负责人)Go (35,000 star) (371 fork)batch import
help wantedscan/secret

描述

Description

Trivy currently skips **/.git for efficiency. https://github.com/aquasecurity/trivy/blob/88702cfd5918b093defc5b5580f7cbf16f5f2417/pkg/fanal/walker/walk.go#L18

However, .git/config could sometimes include credentials (see https://github.com/aquasecurity/trivy/pull/5180#discussion_r1601445169). These directories shouldn't be skipped.

贡献者指南

fix: scan `.git/config` for secrets · aquasecurity/trivy#6699 | Good First Issue