goharbor / harbor

An open source trusted cloud native registry project that stores, signs, and scans content.
https://goharbor.io
Apache License 2.0
24.31k stars 4.77k forks source link

Trivy secret scanning #16898

Closed stroeovidiu closed 2 years ago

stroeovidiu commented 2 years ago

Trivy has support for secret scanning and i was wondering if it is possible to enable that in harbor integration. Can it be done?

Thank you!

stonezdj commented 2 years ago

What is it secret scanning? do you mean image contains secret or scanning by a secret? @danielpacak do you have any idea?

danielpacak commented 2 years ago

Trivy secret scanning is a new functionality to discover sensitive data in container images, e.g. password files, API keys, access tokens, etc.

Even though this functionality is available in Trivy, the Harbor Pluggable Scanners API and Harbor UI are not ready to consume such data. @stroeovidiu is it something you'd like to contribute to by proposing necessary extensions to Pluggable Scanners API?

github-actions[bot] commented 2 years ago

This issue is being marked stale due to a period of inactivity. If this issue is still relevant, please comment or remove the stale label. Otherwise, this issue will close in 30 days.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stalled for 30 days with no activity. If this issue is still relevant, please re-open a new issue.