trivy
trivy copied to clipboard
Keep detected secrets removed in upper layer
Description
Trivy currently scans hard-coded secrets in each layer and ignores a secret if it is removed in the upper layer. It is essential for vulnerability scanning, but on the other hand, removed secrets should be kept in secret scanning.