issues
search
aquasecurity
/
fanal
Static Analysis Library for Containers
Apache License 2.0
199
stars
100
forks
source link
feat: add secret scanning
#431
Closed
knqyf263
closed
2 years ago
knqyf263
commented
2 years ago
Description
It detects secrets such as AWS Access Key and GitHub PAT.
Issues
https://github.com/aquasecurity/trivy/issues/1950
TODO
[x] Add secret analyzer
[x] Add secret scanner
[x] Support secret detection
[x] Support line numbers
[x] Mask secrets
[x] Support custom rules from a config file
[x] Add built-in rules (
https://github.com/aquasecurity/fanal/pull/464
)
[x] Support allow patterns (#443)
[x] Support keywords (#472)
[x] Optimization
[x] Skip some files, dirs and extensions
[x] Skip binaries
[x] Consider container image scanning
[x] Add unit tests
[x] secret/scanner.go
[x] analyzer/secret/secret.go
[x] Add integration tests (will be added in Trivy)
Description
It detects secrets such as AWS Access Key and GitHub PAT.
Issues
TODO