trufflesecurity / trufflehog

Find and verify secrets
https://trufflesecurity.com
GNU Affero General Public License v3.0
14.39k stars 1.57k forks source link

Trufflehog not reporting secrets in docker metadata file #3007

Open venkatasandeeplade opened 1 week ago

venkatasandeeplade commented 1 week ago

Please review the Community Note before submitting

TruffleHog Version

└─$ trufflehog --version trufflehog 3.78.2

Trace Output

Sorry to say , we can't share as per organisation policy Command used trufflehog docker --image=xxxxx.dkr.ecr.us-west-2.amazonaws.com/xx/aiops-pii-mask:1234_abcd_1234

Expected Behavior

Trufflehog should report the secrets exposed in docker config.json/metadata file

Actual Behavior

We have some JFROG passwords in docker metadata / layer information. Trufflehog not reporting them

Environment