← Scan another repo

github.com/k3s-io/k3s

@ f9212d5ae688

Submitted 8/4/2026, 10:28:01 AM · Status: ok

Risk grade
F
100 / 100
Findings
1829
24 critical121 high1201 medium452 low31 info0 on CISA KEV0ATT&CK
Showing 1,829 of 1,829 findings

Findings

  • golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
    grypeCVE-2026-39832EPSS 0.6%
  • golang.org/x/crypto doesn't enforce invoking key constraints
    grypeCVE-2026-39833EPSS 0.4%
  • golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
    grypeCVE-2026-42508EPSS 0.6%
  • golang.org/x/crypto vulnerable to infinite loop on large channel writes
    grypeCVE-2026-39834EPSS 0.5%
  • golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
    grypeCVE-2026-39831EPSS 0.4%
  • golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
    grypeCVE-2026-39830EPSS 0.6%
  • golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
    grypeCVE-2026-46595EPSS 0.5%
  • An egress security group rule allows traffic to /0.
    Opening up ports to connect out to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that are explicitly required where possible.
    trivytests/perf/agents/main.tf:46
  • An egress security group rule allows traffic to /0.
    Opening up ports to connect out to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that are explicitly required where possible.
    trivytests/perf/server/main.tf:56
  • An ingress security group rule allows traffic from /0.
    Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.
    trivytests/perf/agents/main.tf:25
  • An ingress security group rule allows traffic from /0.
    Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.
    trivytests/perf/agents/main.tf:32
  • An ingress security group rule allows traffic from /0.
    Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.
    trivytests/perf/server/main.tf:42
  • An ingress security group rule allows traffic from /0.
    Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.
    trivytests/perf/server/main.tf:28
  • An ingress security group rule allows traffic from /0.
    Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.
    trivytests/perf/server/main.tf:35
  • Manage Kubernetes RBAC resources
    An effective level of access equivalent to cluster-admin should not be provided.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4115
  • Manage secrets
    Viewing secrets at the cluster-scope is akin to cluster-admin in most clusters as there are typically at least one service accounts (their token stored in a secret) bound to cluster-admin directly or a role/clusterrole that gives similar permissions.
    trivytests/integration/longhorn/testdata/longhorn.yaml:3994
  • Manage webhookconfigurations
    Webhooks can silently intercept or actively mutate/block resources as they are being created or updated. This includes secrets and pod specs.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4040
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivymanifests/ccm.yaml:65
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivymanifests/local-storage.yaml:15
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivytests/integration/longhorn/testdata/longhorn.yaml:4115
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivytests/integration/longhorn/testdata/longhorn.yaml:4106
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivytests/integration/longhorn/testdata/longhorn.yaml:4103
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivytests/integration/longhorn/testdata/longhorn.yaml:4100
  • No wildcard verb roles
    Check whether role permits wildcard verb on specific resources
    trivytests/integration/longhorn/testdata/longhorn.yaml:4049
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected kubernetes-secret-yaml: Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deployments
    Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deployments
    gitleaks
  • A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
    grypeCVE-2026-56852EPSS 0.4%
  • Docker: `PUT /containers/{id}/archive` executes container binary on the host
    grypeCVE-2026-41567EPSS 0.1%
  • Docker: Race condition in docker cp allows bind mount redirection to host path
    grypeCVE-2026-42306EPSS 0.1%
  • golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
    grypeCVE-2026-46597EPSS 0.5%
  • golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
    grypeCVE-2026-39829EPSS 0.5%
  • gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    grype
  • Moby has AuthZ plugin bypass when provided oversized request bodies
    grypeCVE-2026-34040EPSS 10.1%
  • Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
    grypeCVE-2026-46600EPSS 0.3%
  • Command injection: exec.Command/exec.CommandContext is invoked with a shell (sh/bash -c) plus an interpolated string, or with argv[0] AND its args spread from the same parsed slice (args[0], args[1:].
    Command injection: exec.Command/exec.CommandContext is invoked with a shell (sh/bash -c) plus an interpolated string, or with argv[0] AND its args spread from the same parsed slice (args[0], args[1:]...) — i.e. a command string split into an argv and executed, which lets input ch…
    semgreppkg/agent/containerd/containerd.go:105
  • 'apk add' is missing '--no-cache'
    You should use 'apk add' with '--no-cache' to clean package cached data and reduce image size.
    trivypackage/Dockerfile:2
  • 'apt-get' missing '--no-install-recommends'
    'apt-get' install should use '--no-install-recommends' to minimize image size.
    trivytests/e2e/scripts/Dockerfile:5
  • A norm.Iter can enter an infinite loop when handling input containing ...
    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
    trivyCVE-2026-56852
  • aws_instance should activate session tokens for Instance Metadata Service.
    IMDS v2 (Instance Metadata Service) introduced session authentication tokens which improve security when talking to IMDS. By default <code>aws_instance</code> resource sets IMDS session auth tokens to be optional. To fully protect IMDS you need to enable session tokens by using…
    trivytests/perf/server/main.tf:148
  • docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload
    Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries …
    trivyCVE-2026-41567
  • github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup
    Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount targe…
    trivyCVE-2026-42306
  • golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
    SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
    trivyCVE-2026-39835
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
    Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
    trivyCVE-2026-46595
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
    An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
    trivyCVE-2026-46597
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
    The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clien…
    trivyCVE-2026-39829
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
    A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now …
    trivyCVE-2026-39830
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
    The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the…
    trivyCVE-2026-39831
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
    When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with Par…
    trivyCVE-2026-39828
  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions
    When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now…
    trivyCVE-2026-39832
  • golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
    Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
    trivyCVE-2026-42508
  • gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
    Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in: - Authorization Bypass (Fai…
    trivy
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile.manifest:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile.test:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivypackage/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivytests/e2e/scripts/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivytests/integration/Dockerfile.test:0
  • Instance with unencrypted block device.
    Block devices should be encrypted to ensure sensitive data is held securely at rest.
    trivytests/perf/server/main.tf:148
  • Load balancer is exposed to the internet.
    There are many scenarios in which you would want to expose a load balancer to the wider internet, but this check exists as a warning to prevent accidental exposure of internal assets. You should ensure that this resource should be exposed publicly.
    trivytests/perf/server/main.tf:100
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4100
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivymanifests/ccm.yaml:44
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivymanifests/local-storage.yaml:15
  • Manage Kubernetes networking
    The ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4118
  • Moby: Moby: Authorization bypass vulnerability
    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
    trivyCVE-2026-34040
  • NET_RAW capability added
    The NET_RAW capability grants attackers the ability to eavesdrop on network traffic or generate IP traffic with falsified source addresses, posing serious security risks.
    trivytests/e2e/amd64_resource_files/multus_test.yaml:29
  • NET_RAW capability added
    The NET_RAW capability grants attackers the ability to eavesdrop on network traffic or generate IP traffic with falsified source addresses, posing serious security risks.
    trivytests/e2e/amd64_resource_files/multus_test.yaml:55
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/integration/longhorn/testdata/pod.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/clusterip.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/daemonset.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/dualstack_clusterip.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/dualstack_nodeport.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/ingress.yaml:32
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/loadbalancer-allTraffic.yaml:19
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/loadbalancer-extTrafficPol.yaml:19
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/loadbalancer-intTrafficPol.yaml:20
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/docker/resources/nodeport.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/clusterip.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/daemonset.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/dualstack_clusterip.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/dualstack_nodeport.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/ingress.yaml:32
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/loadbalancer.yaml:19
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/local-path-provisioner.yaml:13
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/amd64_resource_files/nodeport.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/cis_amd64_resource_files/daemonset.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/e2e/cis_amd64_resource_files/local-path-provisioner.yaml:13
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/integration/etcdrestore/testdata/temp_depl.yaml:0
  • Prevent binding to privileged ports
    The ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.
    trivytests/integration/etcdrestore/testdata/temp_depl2.yaml:0
  • Privileged
    Privileged containers share namespaces with the host system and do not offer any security. They should be used exclusively for system containers that require high privileges.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4242
  • RDS encryption has not been enabled at a DB Instance level.
    Encryption should be enabled for an RDS Database instances. When enabling encryption by setting the kms_key_id.
    trivytests/perf/server/main.tf:60
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/localstorage/testdata/localstorage_pod.yaml:8
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/pod.yaml:8
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/startup/testdata/agnhost.yaml:7
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/startup/testdata/dummy.yaml:9
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivymanifests/local-storage.yaml:68
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivyscripts/airgap/volume-test.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/clusterip.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/daemonset.yaml:15
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/dnsutils.yaml:8
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/dualstack_clusterip.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/dualstack_nodeport.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/hardened-ingress.yaml:22
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/ingress.yaml:49
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/loadbalancer-allTraffic.yaml:35
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/loadbalancer-extTrafficPol.yaml:35
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/loadbalancer-intTrafficPol.yaml:36
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/nodeport.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/pod_client.yaml:18
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/snapshot-test.yaml:7
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/docker/resources/volume-test.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/clusterip.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/daemonset.yaml:15
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/dnsutils.yaml:8
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/dualstack_clusterip.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/dualstack_nodeport.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/ingress.yaml:49
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/loadbalancer.yaml:35
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/local-path-provisioner.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/multus_test.yaml:46
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/multus_test.yaml:72
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/nodeport.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/pod_client.yaml:18
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/wasm-workloads.yaml:18
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/amd64_resource_files/wasm-workloads.yaml:46
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/clusterip.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/daemonset.yaml:15
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/dnsutils.yaml:8
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/loadbalancer.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/local-path-provisioner.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/e2e/cis_amd64_resource_files/nodeport.yaml:16
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/etcdrestore/testdata/temp_depl.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/etcdrestore/testdata/temp_depl2.yaml:21
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4370
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4242
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4449
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4312
  • Root file system is not read-only
    An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.
    trivytests/integration/longhorn/testdata/longhorn.yaml:4366
  • WORKDIR path not absolute
    For clarity and reliability, you should always use absolute paths for your WORKDIR.
    trivytests/e2e/scripts/Dockerfile:17

This report is public.