Skip to finding
important · Supply chain

Public Docker Hub image layers exposed live operational credentials.

Affects

Public Docker Hub images published under Apache, GitLab, Okteto-related, SAP, and Toradex namespaces, with credentials authorizing access to external cloud services.

Unauthenticated image pulls exposed credentials for Apache GitHub, Okteto Terraform, Toradex Slack, GitLab CI and an OpenAI account; validation found administrative or write-capable access among the strongest cases.

Detail and 7 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026