Back to browse
GitHub Repository

layerleak the Docker Hub Secret Scanner

38 starsGo

Layerleak – Like Trufflehog, but for Docker Hub

by brumbelow·Mar 26, 2026·10 points·8 comments

AI Analysis

●●SolidNiche GemBig Brain

Scans Docker Hub layers directly without Docker daemon—Trufflehog for containers.

Strengths
  • No Docker daemon dependency—parses OCI image internals directly from registry.
  • Deduplicates findings by manifest digest with first_seen/last_seen tracking.
  • Scans deleted-layer artifacts that traditional flat-blob scanners miss.
Weaknesses
  • Public Docker Hub only—no private registry or authenticated scan support yet.
  • No secret verification—findings include false positives from test/demo values.
Category
Target Audience

DevSecOps engineers, container security teams

Similar To

Trufflehog · Gitleaks · Docker Scout

Similar Projects

Security●●Solid

MCP-scan – Security scanner for MCP server configs

First security scanner for MCP configs as the protocol gains adoption.

Niche GemShip It
AbanoubRodolf
102mo ago
Security●●●Banger

IDEViewer – Security scanner for malicious IDE Extensions

Scans bundled node_modules inside extensions where standard SCA tools can't see.

Big BrainSolve My Problem
securient
3024d ago