{"repo":"Brumbelow/layerleak","free":true,"listed":false,"github":"https://github.com/Brumbelow/layerleak","clone":"git clone https://github.com/Brumbelow/layerleak.git","description":"layerleak the Docker Hub Secret Scanner","language":"Go","stars":42,"topics":["automation","devsecops","docker","docker-image","dockerhub","go","predeployment","secret","secrets-management","security"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"layerleak Layerleak is a read-only OCI image secret scanner. It resolves public image references without a Docker daemon, verifies downloaded content against OCI digests, reconstructs layer state, inspects deleted artifacts and image metadata, and returns redacted, provenance-rich findings. It supports Docker Hub, GHCR, Quay, GCR, MCR, Amazon ECR Public, and other OCI-compatible registries. Results can be saved as JSON and persisted in PostgreSQL for the bundled API. - Documentation - OpenAPI specification - Changelog - Security policy - Contributing Security model Layerleak scans untrusted image content, so its defaults are intentionally bounded and fail closed: - image, manifest, config, tag response, file, layer, retained-state, and finding limits prevent unbounded work; - manifest, config, and layer bodies are checked against their advertised OCI digests before use; - redirects are capped and revalidated; - private, loopback, link-local, and otherwise non-public registry and auth destinations are blocked unless their exact host is explicitly allowed; - findings, API responses, scan history, and logs are redacted by default; - incomplete coverage is reported as partial or failed , never as a clean scan. Layerleak does not verify whether a detected credential is live. The API has no built-in authentication or authorization; expose it only on a trusted network or behind an authenticated gateway. Install the CLI Layerleak requires Go 1.25.13 or newer. The module root is the c","default_branch":null,"files":null,"tree":[],"storefront":"/r/Brumbelow","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Brumbelow/layerleak/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}