Commit Graph
10 Commits
Author SHA1 Message Date
Mustansir 8aea6cd9da [INS-226] use pinned image for quay registry test (#4602) 2025-12-15 20:35:02 +05:00
Nabeel Alam 674f6262ec Updated the failing Docker source Quay registry test (#4580) 2025-12-03 17:42:25 +05:00
Kashif KhanandShahzad Haider ec61ad98fd Updated Docker source with new test cases and README (#4481)
Co-authored-by: Shahzad Haider <76992801+shahzadhaider1@users.noreply.github.com>
2025-10-16 11:00:44 +05:00
Stephen Aghaulor eafb8c5f6a Add support for docker daemon as a source (#4306)
Now you can scan an image directly after building it with docker build by using the docker:// prefix. This is ideal for local development and CI/CD pipelines that want to ensure images do not contain leaked secrets before pushing to an image registry.

This resolves "Add support for scanning images from the Docker daemon" #4275.

This reverts commit 562dd7242b, which reverted the original version of this change that had some issues with its tests that we did not notice until after we merged it.
2025-07-15 14:21:41 -04:00
Cody Rose 562dd7242b Revert "Added support for scanning images from the docker daemon (#4276)" (#4291)
This reverts commit d7450942da.
2025-07-03 14:38:04 -04:00
Stephen Aghaulor d7450942da Added support for scanning images from the docker daemon (#4276)
- Now you can scan an image directly after building it with `docker build` by using the `docker://` prefix.
  This is ideal for local development and CI/CD pipelines that want to ensure images do not contain leaked secrets before pushing to an image registry.
- Resolves #4275
2025-07-03 13:22:00 -04:00
Tanner Jones 053617c834 feat(docker): implement exclude paths functionality (#4057)
Description:
Add support for excluding paths in Docker source scanning:

Add ExcludePaths field to Docker protobuf
Implement path exclusion logic in docker.go
Add comprehensive test coverage for exact and wildcard path matching
Update engine to pass exclude paths configuration
Add CLI support for --exclude-paths flag
The implementation supports:

Exact path matching (e.g., /var/log/test)
Wildcard path matching (e.g., /var/log/test/*)
Multiple exclude paths
Tests ensure proper handling of:

Exact path exclusions
Wildcard exclusions
Edge cases and similar paths
References:
https://github.com/trufflesecurity/trufflehog/issues/2216?utm_source=chatgpt.com
2025-06-06 14:29:22 -04:00
James Telfer 0024b6ce77 feat: support docker image history scanning (#2882)
* feat: support docker image history scanning

* refactor: collapse error handling into return

Style suggestion from review feedback.

* fix: associate layers with history entries

Where possible, add the associated layer to the history entry record. This may help tracing any issues discovered.

This also changes the entry reference format to `image-metadata:history:%d:created-by` which _may_ be more self-explanatory.
2024-05-28 14:07:43 -07:00
joeleonjr fa9469cfc7 Docker scanning by digest (#1615)
* added functionality to scan docker images with digests instead of tags

* cleaned import statement

* added unit test for baseAndTag parsing + remote digest scan
2023-08-11 16:53:12 -05:00
Dustin Decker e856a6890d 🎉 Add Docker image scanning 🎉 (#1412)
* Add Docker source

* Add metrics

* Add test

* Add debugging, address PR comments, fix path output

* review suggestions
2023-06-22 08:02:25 -07:00