deepfence / deepfence/SecretScanner

Scanning for Secrets in Envs

Open
#124 1 comment 0 reactions 1 assignee Claimed by @ibreakthecloud View on GitHub
enhancement
Dominant language
Go
Stars
3.4k
Forks
346
PR merge metrics
No merged PRs in 30d

Description

The tool should be able to find a Secret in Envs.
For Example, for images that are produced from such Dockerfile:
```
FROM docker.io/library/python:3.8
ENV PYTHONDONTWRITEBYTECODE=1
ENV PYTHONUNBUFFERED=1

WORKDIR /app
COPY requirements.txt /app/
RUN pip install -r requirements.txt

ENV POSTGRES_HOST=database
ENV POSTGRES_USER=postgres
ENV POSTGRES_PASSWORD=postgres
ENV POSTGRES_DB=shopping_list

COPY . /app/

EXPOSE 8000
CMD ["gunicorn", "--bind", "0.0.0.0:8000", "app:app"]
```

It should report the Postgres password.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.