KICS #38
Annotations
1 error and 14 warnings
Upload SARIF file for GitHub Advanced Security Dashboard
Advanced Security must be enabled for this repository to use code scanning.
|
Upload SARIF file for GitHub Advanced Security Dashboard
Advanced Security must be enabled for this repository to use code scanning.
|
Upload SARIF file for GitHub Advanced Security Dashboard
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Advanced Security must be enabled for this repository to use code scanning.
|
Upload SARIF file for GitHub Advanced Security Dashboard
Advanced Security must be enabled for this repository to use code scanning.
|
Upload SARIF file for GitHub Advanced Security Dashboard
Advanced Security must be enabled for this repository to use code scanning.
|
KICS scan:
charts/dim/templates/cronjob-processes.yaml#L37
Check if containers are running with low UID, which might cause conflicts with the host's user table.
|
KICS scan:
charts/dim/templates/deployment.yaml#L39
Check if containers are running with low UID, which might cause conflicts with the host's user table.
|
KICS scan:
charts/dim/templates/deployment.yaml#L39
Containers should be configured with a secure Seccomp profile to restrict potentially dangerous syscalls
|
KICS scan:
charts/dim/templates/cronjob-processes.yaml#L37
Containers should be configured with a secure Seccomp profile to restrict potentially dangerous syscalls
|
KICS scan:
charts/dim/templates/deployment.yaml#L38
Service Account Tokens are automatically mounted even if not necessary
|
KICS scan:
charts/dim/templates/cronjob-processes.yaml#L35
Service Account Tokens are automatically mounted even if not necessary
|
KICS scan:
charts/dim/templates/cronjob-processes.yaml#L20
Cronjobs must have a configured deadline, which means the attribute 'startingDeadlineSeconds' must be defined
|
KICS scan:
charts/dim/templates/deployment.yaml#L32
Deployments should be assigned with a PodDisruptionBudget to ensure high availability
|
KICS scan:
charts/dim/templates/cronjob-processes.yaml#L37
Image Pull Policy of the container must be defined and set to Always
|
KICS scan:
charts/dim/templates/deployment.yaml#L39
Image Pull Policy of the container must be defined and set to Always
|
Loading