Docker
Docker
Edition: Enterprise + Open Source
The Docker integration scans Docker images for credentials and other sensitive data.
Configuration
The Docker integration is configured via a local configuration file. Web configuration in TruffleHog is not available for this source.
Local configuration
Local configuration supports four authentication methods:
- Unauthenticated — for public images that don't require authentication.
- Docker keychain — uses credentials from your local Docker login (docker login).
- Basic authentication — uses a registry username and password.
- Bearer token — uses a registry bearer token.
Images can be specified with or without a tag. If no tag is provided, latest is assumed.
Unauthenticated
Use this for public images that don't require registry authentication.
Docker keychain
Use this when you've already authenticated to your registry locally with docker login. The scanner will use credentials from the Docker keychain.
Basic authentication
Use this for registries that accept username and password credentials.
Bearer token
Use this for registries that accept bearer tokens.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
images | list | Yes | Explicit list of images to scan. Images without a tag default to latest. |
unauthenticated | object | Conditional | Empty object indicating no authentication. Required for unauthenticated mode. |
dockerKeychain | boolean | Conditional | Use credentials from the local Docker keychain. Required for keychain mode. |
basicAuth.username | string | Conditional | Registry username. Required for basic auth mode. |
basicAuth.password | string | Conditional | Registry password. Required for basic auth mode. |
bearerToken | string | Conditional | Registry bearer token. Required for bearer token mode. |
Capabilities
Feature | Supported |
|---|---|
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Notes
- Images must be listed explicitly in the images field. Image enumeration (e.g., scanning all images in a registry or organization) is not supported.
- Only images built for the linux/amd64 platform are scanned. Images built for other architectures (such as linux/arm64 or windows/amd64) are not supported.