Commit 21454ad
committed
File tree
- .github/workflows
- assets/queries
- ansible/aws/memcached_disabled
- test
- azureResourceManager
- account_admins_not_notified_by_email
- aks_cluster_network_policy_not_configured
- aks_cluster_rbac_disabled
- aks_dashboard_enabled
- aks_logging_azure_monitoring_disabled
- aks_with_authorized_ip_ranges_disabled
- app_service_authentication_not_set
- azure_instance_using_basic_authentication
- azure_managed_disk_without_encryption
- email_notifications_set_off
- hardcoded_securestring_parameter_default_value
- key_vault_not_recoverable
- log_profile_incorrect_category
- mysql_server_ssl_enforcement_disabled
- network_security_group_with_unrestricted_access_to_rdp
- network_security_group_with_unrestricted_access_to_ssh
- phone_number_not_set_security_contacts
- postgres_sql_database_server_connection_throttling_disabled
- postgres_sql_server_log_checkpoint_disabled
- postgres_sql_server_log_connections_disabled
- postgres_sql_server_ssl_disabled
- role_definitions_allow_custom_subscription_role_creation
- secret_without_expiration_date
- sql_alert_policy_without_emails
- sql_database_server_firewall_allows_all_ips
- sql_server_database_with_alerts_disabled
- sql_server_database_with_low_retention_days
- sql_server_database_without_auditing
- standard_price_not_selected
- storage_account_allows_network_default_access
- storage_account_allows_unsecure_transfer
- storage_blob_service_container_with_public_access
- storage_logging_for_read_write_delete_requests_disabled
- trusted_microsoft_services_not_enabled
- unrecommended_log_profile_retention_policy
- unrecommended_network_watcher_flow_log_retention_policy
- web_app_not_using_tls_last_version
- website_azure_active_directory_disabled
- website_not_forcing_https
- website_with_client_certificate_auth_disabled
- website_with_http20enabled_disabled
- cloudFormation/aws
- cmk_unencrypted_storage
- test
- default_kms_key_usage
- test
- memcached_disabled
- test
- k8s
- always_admit_admission_control_plugin_set
- always_pull_images_admission_control_plugin_not_set
- anonymous_auth_is_not_set_to_false
- audit_log_maxage_not_properly_set
- audit_log_maxbackup_not_properly_set
- audit_log_maxsize_not_properly_set
- audit_log_path_not_set
- audit_policy_file_not_defined
- audit_policy_not_cover_key_security_concerns
- authorization_mode_node_not_set
- authorization_mode_rbac_not_set
- authorization_mode_set_to_always_allow
- auto_tls_set_to_true
- basic_auth_file_is_set
- bind_address_not_properly_set
- client_certificate_authentication_not_setup_properly
- test
- cluster_admin_role_binding_with_super_user_permissions
- cluster_allows_unsafe_sysctls
- cni_plugin_does_not_support_network_policies
- test
- container_cpu_requests_not_equal_to_its_limits
- container_is_privileged
- container_memory_requests_not_equal_to_its_limits
- container_requests_not_equal_to_its_limits
- container_runs_unmasked
- containers_run_with_low_uid
- containers_running_as_root
- containers_with_added_capabilities
- containers_with_sys_admin_capabilities
- cpu_limits_not_set
- cpu_requests_not_set
- cronjob_deadline_not_configured
- dashboard_is_enabled
- deployment_has_no_pod_anti_affinity
- deployment_without_pod_disruption_budget
- docker_daemon_socket_is_exposed_to_containers
- encryption_provider_config_is_not_defined
- encryption_provider_not_properly_configured
- ensure_administrative_boundaries_between_resources
- test
- etcd_client_certificate_authentication_set_to_false
- etcd_client_certificate_file_not_defined
- etcd_peer_client_certificate_authentication_set_to_false
- etcd_peer_tls_certificate_files_not_properly_set
- etcd_tls_certificate_files_not_properly_set
- etcd_tls_certificate_not_properly_configured
- event_rate_limit_admission_control_plugin_not_set
- hpa_targeted_deployments_with_configured_replica_count
- hpa_targets_invalid_object
- image_policy_webhook_admission_control_plugin_not_set
- image_pull_policy_of_container_is_not_always
- image_without_digest
- incorrect_volume_claim_access_mode_read_write_once
- ingress_controller_exposes_workload
- insecure_bind_address_set
- insecure_port_not_properly_set
- invalid_image
- kubelet_certificate_authority_not_set
- kubelet_client_certificate_or_key_not_set
- kubelet_client_periodic_certificate_switch_disabled
- kubelet_event_qps_not_properly_set
- kubelet_hostname_override_is_set
- kubelet_https_set_to_false
- kubelet_not_managing_ip_tables
- kubelet_protect_kernel_defaults_set_to_false
- kubelet_read_only_port_is_not_set_to_zero
- kubelet_streaming_connection_timeout_disabled
- liveness_probe_is_not_defined
- memory_limits_not_defined
- memory_requests_not_defined
- metadata_label_is_invalid
- missing_app_armor_config
- namespace_lifecycle_admission_control_plugin_disabled
- net_raw_capabilities_disabled_for_psp
- net_raw_capabilities_not_being_dropped
- network_policy_is_not_targeting_any_pod
- no_drop_capabilities_for_containers
- node_restriction_admission_control_plugin_not_set
- non_kube_system_pod_with_host_mount
- not_limited_capabilities_for_container
- not_limited_capabilities_for_pod_security_policy
- not_unique_certificate_authority
- object_is_using_a_deprecated_api_version
- peer_auto_tls_set_to_true
- permissive_access_to_create_pods
- pod_misconfigured_network_policy
- pod_or_container_without_limit_range
- pod_or_container_without_resource_quota
- pod_or_container_without_security_context
- pod_security_policy_admission_control_plugin_not_set
- privilege_escalation_allowed
- profiling_not_set_to_false
- psp_allows_privilege_escalation
- psp_allows_sharing_host_ipc
- psp_allows_sharing_host_pid
- psp_set_to_privileged
- psp_with_added_capabilities
- psp_with_unrestricted_access_to_host_path
- rbac_roles_allow_privilege_escalation
- rbac_roles_with_exec_permission
- rbac_roles_with_impersonate_permission
- rbac_roles_with_portforwarding_permissions
- rbac_roles_with_read_secrets_permissions
- rbac_wildcard_in_rule
- readiness_probe_is_not_configured
- request_timeout_not_properly_set
- role_binding_to_default_service_account
- root_ca_file_not_defined
- root_container_not_mounted_as_read_only
- root_containers_admitted
- rotate_kubelet_server_certificate_not_active
- seccomp_profile_is_not_configured
- secrets_as_environment_variables
- secure_port_set_to_zero
- security_context_deny_admission_control_plugin_not_set
- service_account_admission_control_plugin_disabled
- service_account_allows_access_secrets
- service_account_key_file_not_properly_set
- service_account_lookup_set_to_false
- service_account_name_undefined_or_empty
- service_account_private_key_file_not_defined
- service_account_token_automount_not_disabled
- service_does_not_target_pod
- service_type_is_nodeport
- service_with_external_load_balance
- statefulset_has_no_pod_anti_affinity
- statefulset_requests_storage
- statefulset_without_pod_disruption_budget
- statefulset_without_service_name
- terminated_pod_garbage_collector_threshold_not_properly_set
- tiller_deployment_is_accessible_from_within_the_cluster
- tiller_is_deployed
- tiller_service_is_not_deleted
- tls_connection_certificate_not_setup
- token_auth_file_is_set
- use_service_account_credentials_not_set_to_true
- using_kubernetes_native_secret_management
- using_unrecommended_namespace
- volume_mount_with_os_directory_write_permissions
- weak_tls_cipher_suites
- workload_host_port_not_specified
- workload_mounting_with_sensitive_os_directory
- terraform/aws/memcached_disabled
- test
- docker
- docs
- docker
- internal
- console
- helpers
- metrics
- pkg
- analyzer
- detector
- engine
- release
- test
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
12 | | - | |
| 11 | + | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
96 | 99 | | |
97 | 100 | | |
98 | 101 | | |
99 | 102 | | |
100 | | - | |
| 103 | + | |
101 | 104 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| |||
141 | 141 | | |
142 | 142 | | |
143 | 143 | | |
144 | | - | |
| 144 | + | |
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
| |||
153 | 153 | | |
154 | 154 | | |
155 | 155 | | |
156 | | - | |
| 156 | + | |
157 | 157 | | |
158 | 158 | | |
159 | 159 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
84 | | - | |
| 84 | + | |
85 | 85 | | |
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | | - | |
| 89 | + | |
90 | 90 | | |
91 | 91 | | |
92 | 92 | | |
| |||
96 | 96 | | |
97 | 97 | | |
98 | 98 | | |
99 | | - | |
| 99 | + | |
100 | 100 | | |
101 | 101 | | |
102 | 102 | | |
103 | 103 | | |
104 | | - | |
| 104 | + | |
105 | 105 | | |
106 | 106 | | |
107 | 107 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | | - | |
| 68 | + | |
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
82 | | - | |
| 82 | + | |
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
56 | | - | |
| 56 | + | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
| 59 | + | |
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| |||
175 | 175 | | |
176 | 176 | | |
177 | 177 | | |
178 | | - | |
| 178 | + | |
179 | 179 | | |
180 | 180 | | |
181 | 181 | | |
| |||
188 | 188 | | |
189 | 189 | | |
190 | 190 | | |
191 | | - | |
| 191 | + | |
192 | 192 | | |
193 | 193 | | |
194 | 194 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
| 50 | + | |
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
172 | 172 | | |
173 | 173 | | |
174 | 174 | | |
175 | | - | |
| 175 | + | |
176 | 176 | | |
177 | 177 | | |
178 | 178 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
0 commit comments