Hacker Newsnew | past | comments | ask | show | jobs | submit | brumbelow's commentslogin

Thanks for the advice! Did not even consider that. I just updated it

I couldn't find anything comparable to Trufflehog for Docker images, even though I have constantly read articles about "secrets discovered in public images." So I built my own (hopefully) comparable tool.

But trufflehog supports docker images already? The trufflehog readme has examples[0]

    # to scan from a remote registry
    trufflehog docker --image trufflesecurity/secrets 
    # to scan from the local docker daemon

    trufflehog docker --image docker://new_image:tag

    # to scan from an image saved as a tarball
    trufflehog docker --image file://path_to_image.tar
[0]: https://github.com/trufflesecurity/trufflehog#11-scan-a-dock...

That's true, but as you can see from your paste, Trufflehog requires the docker daemon and is generally pretty resource intensive while scanning.

layerleak has neither of those issues or requirements.

Try it and let me know what you think.


> That's true, but as you can see from your paste, Trufflehog requires the docker daemon and is generally pretty resource intensive while scanning.

Nothing in his message says it requires the docker daemon? it says it can scan an image from a docker daemon if you want.

I just tried myself and it doesn't require docker at all, you don't need anything docker related even installed on the system.

I tried them both to compare:

- trufflehog: 19 seconds

- layerleak: 26 seconds


His paste literally says...

" # to scan from the local docker daemon"

That aside, I just tested against trufflehog myself. It did take about 10-15%longer for a scan to complete but this is expected. Layerleak is scanning any additional or deleted tags found for the digest while trufflehog only scans the one. I am proud of the project, so I am showing it off. If you dont like, dont use :)

Thanks for checking it out.


Yeah, like I explained you CAN use an image from a docker daemon if you WANT to:

    trufflehog docker --image docker://new_image:tag
If you don't want to scan from a docker daemon then, you can pull from docker hub:

    trufflehog docker --image trufflesecurity/secrets 
or from a tarball:

    trufflehog docker --image file://path_to_image.tar

This is a cool idea. The stage-by-stage build makes the failure modes legible: first the loop, then tool dispatch, then persistence, then subagents/skills/compaction. A nice reminder that most of the magic is in state management and control flow

I wouldn't say most of the magic is there, but I do think a lot of the progress we've seen in the last few years has been external to the models, and people sometimes miss that. For example, Claude Code has improved by leaps and bounds because the tooling has improved so much, from what I can see. But the underlying model is still what makes this relatively simple tooling so useful.

Agreed. That's the core hypothesis behind this learning project — model is the magic, and the agent loop is just a thin, transparent wrapper around it. The goal of building it stage-by-stage was to prove you don't need a massive, complex framework to get good agentic behavior.

“Antimatter in a truck” is great headline material, but the actual advance is portable precision instrumentation.

CERN can make/store the antiprotons, but not measure them as cleanly as they want because the facility itself introduces tiny magnetic fluctuations. So this is really a story about moving the sample to a quieter lab, not moving toward sci-fi antimatter batteries... for now


Yeah, it's really impressive to me that they can make antiparticles, put them in a container, count them, transport them and count them again.

Nonetheless, "moving antimatter by truck" is pretty SF. More grounded than epic space opera, but stillvery cool.

It almost could be a Hollywood movie in the vein of Sorceror. Couple of grizzled CERN vets transporting a volatile load of antimatter across a post-apocalyptic wasteland while being chased by energy terrorists.

"More grounded..." I see what you did there ;P

“I have had it with these anti-matter protons on this anti-matter truck!”

Or something.


Next milestone: put it in Warptruck™ as fuel

A certain car company CEO is about to announce the availability of that in "5-10 years"

AI slop account

It is. The new meta is posting LLM comments, but then if called out post a human response. So it appears as if you were just mistaken, and this was always a human posting.

People should read the comment history more critically.


wtf? you're slop lol

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: