Scan your Harbor container registry for secrets
Release Date: October 9, 2026
![]()
Harbor is where many teams keep the images they ship to production, on their own infrastructure and often behind their own firewall. Those images regularly carry what nobody meant to ship: a database password in an ENV directive, a cloud key copied into a config file, a token left in a build layer.
GitGuardian now scans your Harbor registry with the same detection engine and incident workflow as your repositories.
What does this mean for you?
- Every tagged image, every layer: GitGuardian scans all layers of your tagged images, including each platform of a multi-architecture image, along with Dockerfiles and the environment variables in image metadata.
- Read-only access you control: the integration uses a Harbor robot account with list and pull permissions only. You create it, you scope it, and you can disable it at any time.
- Works behind your firewall: connect a Harbor instance that is not reachable from the internet through GitGuardian Bridge.
- You choose what is monitored: select specific Harbor repositories, or monitor the entire instance and have new repositories added automatically.
- Historical and incremental scanning: catch the secrets already hiding in existing images, and the ones in images pushed later.
- Health you can see: GitGuardian flags an installation whose robot account expired, lost its permissions, or became unreachable, and you can rotate its secret without reinstalling.
Why is this important?
A container image is the last artifact before production. A secret baked into one of its layers travels straight to your runtime, and every system that can pull the image can read it. Image layers rarely go through the reviews source code gets, which makes them an easy place for credentials to hide.
With Harbor joining Docker Hub, Amazon ECR, Azure Container Registry, Google Artifact Registry, JFrog Container Registry and Red Hat Quay, GitGuardian now covers seven container registries, so you get the same secrets detection wherever your images live.
Get Started Today!
- In Harbor, create a system-level robot account with Repository (
List,Pull) and Artifact (List,Read) permissions. - Navigate to Settings > Integrations > Sources and click Install next to Harbor in the Container registries section.
- Enter your Harbor URL and the robot account name, including its
robot$prefix, and secret, then choose your monitored perimeter.
This integration is available in beta. Check out the full setup guide to learn more.















