Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
Dockerfile
>
General
>
Do Not Pass Secrets
CRITICAL
Source
Trivy
ID
AVD-DS-0031
Secrets passed via
build-args
or envs or copied secret files
Passing secrets via
build-args
or envs or copying secret files can leak them out
Impact
Links
https://docs.docker.com/build/building/secrets/
Aqua Container Security