Hacker News new | ask | show | jobs
by 8organicbits 903 days ago
I think Trivy does that already [1]. I personally use trufflehog [2] to find secrets of all kinds. Unfortunately, these sorts of tools have false positives

[1] https://aquasecurity.github.io/trivy/v0.27.1/docs/secret/sca...

[2] https://github.com/trufflesecurity/trufflehog