AVD-DS-0031 (leaked secrets) wrongly check fails for every Dockerfile #7825
Closed
pjungermann
started this conversation in
False Detection
Replies: 1 comment 3 replies
-
Hi @pjungermann ! A PR is open to fix this problem |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
AVD-DS-0031 (DS031)
Description
The leaked secrets check fails for every Dockerfile without any actual matches to the regular expression used.
Excerpt from
-f json
outputI used Trivy installed via Homebrew as well as part of megalinter-security executed within Bitbucket Pipelines.
Reproduction Steps
Target
Filesystem
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions