Skip to content

update: bump bridgecrewio/checkov-action from 12.2401.0 to 12.2408.0 #4033

update: bump bridgecrewio/checkov-action from 12.2401.0 to 12.2408.0

update: bump bridgecrewio/checkov-action from 12.2401.0 to 12.2408.0 #4033

Status Success
Total duration 5m 52s
Artifacts 3

cicd.yaml

on: pull_request
Matrix: integration-test / k8s-versions
Matrix: integration-test / integration test
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 2 warnings
sast / checkov: deployment/deployment.yaml#L3
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L26
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L42
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L56
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L117
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L138
CKV_K8S_49: "Minimize wildcard use in Roles and ClusterRoles"
sast / checkov: deployment/deployment.yaml#L174
CKV_K8S_21: "The default namespace should not be used"
sast / checkov: deployment/deployment.yaml#L195
CKV_K8S_35: "Prefer using secrets as files over secrets as environment variables"
sast / checkov: deployment/deployment.yaml#L195
CKV_K8S_38: "Ensure that Service Account Tokens are only mounted where necessary"
sast / checkov: deployment/deployment.yaml#L195
CKV_K8S_43: "Image should use digest"
sca / syft / dependency review
Error uploading depdendency snapshot: { "url": "https://api.github.com/repos/sse-secure-systems/connaisseur/dependency-graph/snapshots", "status": 422, "headers": { "access-control-allow-origin": "*", "access-control-expose-headers": "ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset", "connection": "close", "content-length": "281", "content-security-policy": "default-src 'none'", "content-type": "application/json; charset=utf-8", "date": "Mon, 03 Jul 2023 03:41:14 GMT", "referrer-policy": "origin-when-cross-origin, strict-origin-when-cross-origin", "server": "GitHub.com", "strict-transport-security": "max-age=31536000; includeSubdomains; preload", "vary": "Accept-Encoding, Accept, X-Requested-With", "x-content-type-options": "nosniff", "x-frame-options": "deny", "x-github-api-version-selected": "2022-11-28", "x-github-media-type": "github.v3; format=json", "x-github-request-id": "5480:866C:144FACB:1553F98:64A2435A", "x-ratelimit-limit": "100", "x-ratelimit-remaining": "99", "x-ratelimit-reset": "1688355734", "x-ratelimit-resource": "dependency_snapshots", "x-ratelimit-used": "1", "x-xss-protection": "0" }, "data": { "message": "invalid package url: in manifest \"ghcr.io/sse-secure-systems/connaisseur-test:sha-d49f58b:/bin/busybox\" decoding \"\": scheme is missing", "documentation_url": "https://docs.github.com/rest/reference/dependency-graph#create-a-snapshot-of-dependencies-for-a-repository" } }
sca / grype
Failed minimum severity level. Found vulnerabilities with level 'medium' or higher

Artifacts

Produced during runtime
Name Size
cosign.pub Expired
178 Bytes
sbom.cdx Expired
652 KB
sse-secure-systems-connaisseur-test_sha-d49f58b.cyclonedx.json Expired
713 KB