INFRA Signal 376
vamp-secrets-scanner 2.4 released with Docker and Kubernetes scanning
Static secrets and credentials scanner with git history analysis, Shannon entropy detection, SARIF 2.1.0 output, Docker runtime scanning and Kubernetes Secrets scanning
The release of vamp-secrets-scanner 2.4 introduces enhanced capabilities for detecting secrets and credentials in static codebases. This is particularly important for organizations using Docker and Kubernetes, as it helps secure sensitive information within their deployments. By integrating features like Shannon entropy detection and SARIF output, it provides a more comprehensive tool for developers and security teams.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The new version includes Docker runtime scanning to identify secrets in containerized applications.
Kubernetes Secrets scanning capability enhances security for Kubernetes deployments.
The addition of SARIF 2.1.0 output format supports better integration with other security tools.
THE CLUSTER