Skip to main content
Version: v0.19.0

secret-scan

No secrets or credentials should be embedded in the image.

ProviderLevelTags
trivyCriticalsecurity

Parameters

NameDefault ValueDescription
max_count0n/a

Messages

TypeMessage
PassNo secrets detected in the image.
FailTrivy detected ${results.trivy.secrets_count} secrets or credentials in the image.

Playbook Example

rules:
- provider: trivy
rule: secret-scan
options:
max_count: 0

Condition

{
"<=": [
{
"var": "results.trivy.secrets_count"
},
{
"var": "rule.params.max_count"
}
]
}