Risk grade
F
100 / 100
Findings
1829
24 critical121 high1201 medium452 low31 info0 on CISA KEV0ATT&CK
Showing 1,829 of 1,829 findings
Findings
- golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keysgrypeCVE-2026-39832EPSS 0.6%
- golang.org/x/crypto doesn't enforce invoking key constraintsgrypeCVE-2026-39833EPSS 0.4%
- golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked statusgrypeCVE-2026-42508EPSS 0.6%
- golang.org/x/crypto vulnerable to infinite loop on large channel writesgrypeCVE-2026-39834EPSS 0.5%
- golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassedgrypeCVE-2026-39831EPSS 0.4%
- golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responsesgrypeCVE-2026-39830EPSS 0.6%
- golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcementgrypeCVE-2026-46595EPSS 0.5%
- An egress security group rule allows traffic to /0.Opening up ports to connect out to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that are explicitly required where possible.trivytests/perf/agents/main.tf:46
- An egress security group rule allows traffic to /0.Opening up ports to connect out to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that are explicitly required where possible.trivytests/perf/server/main.tf:56
- An ingress security group rule allows traffic from /0.Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.trivytests/perf/agents/main.tf:25
- An ingress security group rule allows traffic from /0.Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.trivytests/perf/agents/main.tf:32
- An ingress security group rule allows traffic from /0.Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.trivytests/perf/server/main.tf:42
- An ingress security group rule allows traffic from /0.Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.trivytests/perf/server/main.tf:28
- An ingress security group rule allows traffic from /0.Opening up ports to the public internet is generally to be avoided. You should restrict access to IP addresses or ranges that explicitly require it where possible.trivytests/perf/server/main.tf:35
- Manage Kubernetes RBAC resourcesAn effective level of access equivalent to cluster-admin should not be provided.trivytests/integration/longhorn/testdata/longhorn.yaml:4115
- Manage secretsViewing secrets at the cluster-scope is akin to cluster-admin in most clusters as there are typically at least one service accounts (their token stored in a secret) bound to cluster-admin directly or a role/clusterrole that gives similar permissions.trivytests/integration/longhorn/testdata/longhorn.yaml:3994
- Manage webhookconfigurationsWebhooks can silently intercept or actively mutate/block resources as they are being created or updated. This includes secrets and pod specs.trivytests/integration/longhorn/testdata/longhorn.yaml:4040
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivymanifests/ccm.yaml:65
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivymanifests/local-storage.yaml:15
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivytests/integration/longhorn/testdata/longhorn.yaml:4115
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivytests/integration/longhorn/testdata/longhorn.yaml:4106
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivytests/integration/longhorn/testdata/longhorn.yaml:4103
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivytests/integration/longhorn/testdata/longhorn.yaml:4100
- No wildcard verb rolesCheck whether role permits wildcard verb on specific resourcestrivytests/integration/longhorn/testdata/longhorn.yaml:4049
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected kubernetes-secret-yaml: Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deploymentsPossible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deploymentsgitleaks
- A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.grypeCVE-2026-56852EPSS 0.4%
- Docker: `PUT /containers/{id}/archive` executes container binary on the hostgrypeCVE-2026-41567EPSS 0.1%
- Docker: Race condition in docker cp allows bind mount redirection to host pathgrypeCVE-2026-42306EPSS 0.1%
- golang.org/x/crypto: Invoking byte arithmetic causes underflow and panicgrypeCVE-2026-46597EPSS 0.5%
- golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoSgrypeCVE-2026-39829EPSS 0.5%
- gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilitiesgrype
- Moby has AuthZ plugin bypass when provided oversized request bodiesgrypeCVE-2026-34040EPSS 10.1%
- Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.grypeCVE-2026-46600EPSS 0.3%
- Command injection: exec.Command/exec.CommandContext is invoked with a shell (sh/bash -c) plus an interpolated string, or with argv[0] AND its args spread from the same parsed slice (args[0], args[1:].Command injection: exec.Command/exec.CommandContext is invoked with a shell (sh/bash -c) plus an interpolated string, or with argv[0] AND its args spread from the same parsed slice (args[0], args[1:]...) — i.e. a command string split into an argv and executed, which lets input ch…semgreppkg/agent/containerd/containerd.go:105
- 'apk add' is missing '--no-cache'You should use 'apk add' with '--no-cache' to clean package cached data and reduce image size.trivypackage/Dockerfile:2
- 'apt-get' missing '--no-install-recommends''apt-get' install should use '--no-install-recommends' to minimize image size.trivytests/e2e/scripts/Dockerfile:5
- A norm.Iter can enter an infinite loop when handling input containing ...A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.trivyCVE-2026-56852
- aws_instance should activate session tokens for Instance Metadata Service.IMDS v2 (Instance Metadata Service) introduced session authentication tokens which improve security when talking to IMDS. By default <code>aws_instance</code> resource sets IMDS session auth tokens to be optional. To fully protect IMDS you need to enable session tokens by using…trivytests/perf/server/main.tf:148
- docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive uploadMoby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries …trivyCVE-2026-41567
- github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setupMoby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount targe…trivyCVE-2026-42306
- golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificateSSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.trivyCVE-2026-39835
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validationPreviously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.trivyCVE-2026-46595
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputsAn incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.trivyCVE-2026-46597
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parametersThe RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clien…trivyCVE-2026-39829
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responsesA malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now …trivyCVE-2026-39830
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence checkThe Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the…trivyCVE-2026-39831
- golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissionsWhen an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with Par…trivyCVE-2026-39828
- golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictionsWhen adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now…trivyCVE-2026-39832
- golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKeyPreviously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.trivyCVE-2026-42508
- gRPC-Go: xDS RBAC and HTTP/2 VulnerabilitiesMultiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in: - Authorization Bypass (Fai…trivy
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyDockerfile.manifest:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyDockerfile.test:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyDockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivypackage/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivytests/e2e/scripts/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivytests/integration/Dockerfile.test:0
- Instance with unencrypted block device.Block devices should be encrypted to ensure sensitive data is held securely at rest.trivytests/perf/server/main.tf:148
- Load balancer is exposed to the internet.There are many scenarios in which you would want to expose a load balancer to the wider internet, but this check exists as a warning to prevent accidental exposure of internal assets. You should ensure that this resource should be exposed publicly.trivytests/perf/server/main.tf:100
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivytests/integration/longhorn/testdata/longhorn.yaml:4100
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivymanifests/ccm.yaml:44
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivymanifests/local-storage.yaml:15
- Manage Kubernetes networkingThe ability to control which pods get service traffic directed to them allows for interception attacks. Controlling network policy allows for bypassing lateral movement restrictions.trivytests/integration/longhorn/testdata/longhorn.yaml:4118
- Moby: Moby: Authorization bypass vulnerabilityMoby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.trivyCVE-2026-34040
- NET_RAW capability addedThe NET_RAW capability grants attackers the ability to eavesdrop on network traffic or generate IP traffic with falsified source addresses, posing serious security risks.trivytests/e2e/amd64_resource_files/multus_test.yaml:29
- NET_RAW capability addedThe NET_RAW capability grants attackers the ability to eavesdrop on network traffic or generate IP traffic with falsified source addresses, posing serious security risks.trivytests/e2e/amd64_resource_files/multus_test.yaml:55
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/integration/longhorn/testdata/pod.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/clusterip.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/daemonset.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/dualstack_clusterip.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/dualstack_nodeport.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/ingress.yaml:32
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/loadbalancer-allTraffic.yaml:19
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/loadbalancer-extTrafficPol.yaml:19
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/loadbalancer-intTrafficPol.yaml:20
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/docker/resources/nodeport.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/clusterip.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/daemonset.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/dualstack_clusterip.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/dualstack_nodeport.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/ingress.yaml:32
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/loadbalancer.yaml:19
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/local-path-provisioner.yaml:13
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/amd64_resource_files/nodeport.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/cis_amd64_resource_files/daemonset.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/e2e/cis_amd64_resource_files/local-path-provisioner.yaml:13
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/integration/etcdrestore/testdata/temp_depl.yaml:0
- Prevent binding to privileged portsThe ports which are lower than 1024 receive and transmit various sensitive and privileged data. Allowing containers to use them can bring serious implications.trivytests/integration/etcdrestore/testdata/temp_depl2.yaml:0
- PrivilegedPrivileged containers share namespaces with the host system and do not offer any security. They should be used exclusively for system containers that require high privileges.trivytests/integration/longhorn/testdata/longhorn.yaml:4242
- RDS encryption has not been enabled at a DB Instance level.Encryption should be enabled for an RDS Database instances. When enabling encryption by setting the kms_key_id.trivytests/perf/server/main.tf:60
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/localstorage/testdata/localstorage_pod.yaml:8
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/pod.yaml:8
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/startup/testdata/agnhost.yaml:7
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/startup/testdata/dummy.yaml:9
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivymanifests/local-storage.yaml:68
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivyscripts/airgap/volume-test.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/clusterip.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/daemonset.yaml:15
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/dnsutils.yaml:8
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/dualstack_clusterip.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/dualstack_nodeport.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/hardened-ingress.yaml:22
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/ingress.yaml:49
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/loadbalancer-allTraffic.yaml:35
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/loadbalancer-extTrafficPol.yaml:35
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/loadbalancer-intTrafficPol.yaml:36
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/nodeport.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/pod_client.yaml:18
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/snapshot-test.yaml:7
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/docker/resources/volume-test.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/clusterip.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/daemonset.yaml:15
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/dnsutils.yaml:8
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/dualstack_clusterip.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/dualstack_nodeport.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/ingress.yaml:49
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/loadbalancer.yaml:35
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/local-path-provisioner.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/multus_test.yaml:46
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/multus_test.yaml:72
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/nodeport.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/pod_client.yaml:18
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/wasm-workloads.yaml:18
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/amd64_resource_files/wasm-workloads.yaml:46
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/clusterip.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/daemonset.yaml:15
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/dnsutils.yaml:8
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/loadbalancer.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/local-path-provisioner.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/e2e/cis_amd64_resource_files/nodeport.yaml:16
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/etcdrestore/testdata/temp_depl.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/etcdrestore/testdata/temp_depl2.yaml:21
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/longhorn.yaml:4370
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/longhorn.yaml:4242
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/longhorn.yaml:4449
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/longhorn.yaml:4312
- Root file system is not read-onlyAn immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.trivytests/integration/longhorn/testdata/longhorn.yaml:4366
- WORKDIR path not absoluteFor clarity and reliability, you should always use absolute paths for your WORKDIR.trivytests/e2e/scripts/Dockerfile:17
This report is public.