chiprook
← Security
SecuritySeptember 16, 2026, 09:15

Deleting a secret from your Docker image doesn't delete it from your build history

An autonomous hacking agent found a live GitHub admin token in a public Docker image from Baseten: the token from March 2023 persisted in the build history and in July 2026 still granted admin access to internal repositories. The secret was not in filesystem layers but in the image config — a RUN command exposed GITHUB_TOKEN in history[].created_by.

Deleting a secret from your Docker image doesn't delete it from your build history
#Docker#GitHub#Baseten
Read next
Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto

Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera