Skip to content

Conversation

@lindycoder
Copy link

The story that added this was aimed only at updating trivy-image since that's the only secret scanning we currently have for images.

For source-code, without proper benchmarking, we don't want to offer trivy secret scanning as an alternative to gitleaks. Maybe it will come but not for now.

This change will prevent the trivy-fs scans from bearing the "secrets" scan-type which shows up in the secret section of the scanner coverage.

The story that added this was aimed only at updating trivy-image since
that's the only secret scanning we currently have for images.

For source-code, without proper benchmarking, we don't want to offer
trivy secret scanning as an alternative to gitleaks.  Maybe it will come
but not for now.

This change will prevent the trivy-fs scans from bearing the "secrets"
scan-type which shows up in the secret section of the scanner coverage.
@lindycoder lindycoder marked this pull request as ready for review November 14, 2025 18:13
@lindycoder lindycoder merged commit 6817608 into main Nov 14, 2025
4 checks passed
@lindycoder lindycoder deleted the BST-17950-revert-trivy-fs-secrets branch November 14, 2025 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants