diff --git a/rules/S6437/docker/rule.adoc b/rules/S6437/docker/rule.adoc index c3d49dc3563..31d6fa2e258 100644 --- a/rules/S6437/docker/rule.adoc +++ b/rules/S6437/docker/rule.adoc @@ -17,6 +17,10 @@ include::../../../shared_content/secrets/impact/financial_loss.adoc[] include::../../../shared_content/secrets/impact/security_downgrade.adoc[] +=== Exceptions + +In multi-stage builds, the rule only checks instructions that are part of the final image. + == How to fix it Best practices recommend using a secret vault for all secrets that must be