Added a new section to the deployments docs #1462
88 new alerts including 18 errors
New alerts in code changed by this pull request
- 18 errors
- 70 notes
See annotations below for details.
Annotations
Code scanning / checkov
Ensure top-level permissions are not set to write-all Error documentation
Code scanning / checkov
Ensure top-level permissions are not set to write-all Error documentation
Code scanning / checkov
The default namespace should not be used Note documentation
Code scanning / checkov
Containers should not run with allowPrivilegeEscalation Error documentation
Code scanning / checkov
Apply security context to your containers Note documentation
Code scanning / checkov
CPU limits should be set Note documentation
Code scanning / checkov
CPU requests should be set Note documentation
Code scanning / checkov
The default namespace should not be used Note documentation
Code scanning / checkov
Minimize the admission of containers with the NET_RAW capability Note documentation
Code scanning / checkov
Image should use digest Note documentation
Code scanning / checkov
Image Tag should be fixed - not latest or blank Note documentation
Code scanning / checkov
Liveness Probe Should be Configured Note documentation
Code scanning / checkov
Memory limits should be set Note documentation
Code scanning / checkov
Memory requests should be set Note documentation
Code scanning / checkov
Minimize the admission of containers with capabilities assigned Note documentation
Code scanning / checkov
Apply security context to your pods and containers Note documentation
Code scanning / checkov
Readiness Probe Should be Configured Note documentation
Code scanning / checkov
Use read-only filesystem for containers where possible Note documentation
Code scanning / checkov
Minimize the admission of root containers Error documentation
Code scanning / checkov
Containers should run as a high UID to avoid host conflict Note documentation
Code scanning / checkov
Ensure that the seccomp profile is set to docker/default or runtime/default Note documentation
Code scanning / checkov
Prefer using secrets as files over secrets as environment variables Note documentation
Code scanning / checkov
Ensure that Service Account Tokens are only mounted where necessary Note documentation
Code scanning / checkov
Minimize the admission of pods which lack an associated NetworkPolicy Error documentation
Code scanning / checkov
The default namespace should not be used Note documentation