feat: add renderer pipeline support to manifest generation in #483
65 new alerts including 10 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 10 high
- 13 medium
- 42 low
See annotations below for details.
Annotations
Check notice on line 7 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Workloads in the default namespace Low test
Check failure on line 15 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Default security context configured High test
Check warning on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Can elevate its own privileges Medium test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop all Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop any Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
CPU not limited Low test
Check warning on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Runs as root user Medium test
Check failure on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Root file system is not read-only High test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
CPU requests not specified Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Memory requests not specified Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Memory not limited Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Runs with UID <= 10000 Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Runs with GID <= 10000 Low test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Runtime/Default Seccomp profile not set Low test
Check warning on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Seccomp policies disabled Medium test
Check notice on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Container capabilities must only include NET_BIND_SERVICE Low test
Check failure on line 14 in test/mixed/helm/yet-another-cloudwatch-exporter/templates/job.yaml
Code scanning / Trivy
Default security context configured High test
Check notice on line 4 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Workloads in the default namespace Low test
Check failure on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Default security context configured High test
Check warning on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Can elevate its own privileges Medium test
Check notice on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop all Low test
Check notice on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop any Low test
Check warning on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Runs as root user Medium test
Check failure on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
Root file system is not read-only High test
Check notice on line 26 in test/mixed/kustomize/base/deployment.yaml
Code scanning / Trivy
CPU requests not specified Low test