OWASP / Docker-Security

Getting a handle on container security
https://owasp.org/www-project-docker-top-10/
Other
625 stars 130 forks source link

Update D06 - Protect Secrets.md #39

Closed Aut0R3V closed 3 years ago

Aut0R3V commented 3 years ago

Add details on how to prevent secret leakage

Aut0R3V commented 3 years ago

@drwetter can you please recommend required changes here?

drwetter commented 3 years ago

As said I believe it's easier if you start not with the bottom line.

Besides it is not good. NOt sure you got why using environment variables is bad when you're claiming a counter measure is rotating them??