Over 10,000 Docker Hub images found leaking credentials, auth keys

7 points by yashgarg


mdaniel

I'm jealous of having the compute required to conduct this scan, but my favorite(sic) anti-pattern is this nonsense:

COPY .aws/credentials /root/.aws
RUN aws do-something-awesome
RUN rm -rf /root/.aws && echo now is sekure!!