fix: scan .git/config
for secrets
#6699
Labels
help wanted
Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
scan/secret
Issues relating to secret scanning
Description
Trivy currently skips
**/.git
for efficiency.trivy/pkg/fanal/walker/walk.go
Line 18 in 88702cf
However,
.git/config
could sometimes include credentials (see #5180 (comment)). These directories shouldn't be skipped.The text was updated successfully, but these errors were encountered: