[Secret scanning] Trivy mistakenly reports gpg/RSA key hash contained in README (Markdown) as "AWS secret access key" #5974
Closed
codethief
started this conversation in
False Detection
Replies: 1 comment
-
Duplicate of #5900 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
/
Description
Running Trivy on my image that comes with
gitpython
pip package (v3.1.41) yields a "critical" vulnerability related to an "AWS Secret Access Key".However, the offending line (effectively) is this one: https://github.com/gitpython-developers/GitPython/blob/3.1.41/README.md?plain=1#L246 .
MANIFEST
file.Reproduction Steps
Target
Container Image
Scanner
Secret
Target OS
Debian 12 "Bookworm" (more specifically "buildpack-deps:bookworm")
Debug Output
Relevant output of
--debug -f json
:Beta Was this translation helpful? Give feedback.
All reactions