feat: Ensure env-vars changes are always immediately applied #399
29 new alerts including 3 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 3 high
- 14 medium
- 12 low
See annotations below for details.
Annotations
Check warning on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Can elevate its own privileges Medium
Check notice on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop all Low
Check warning on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Runs as root user Medium
Check failure on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Root file system is not read-only High
Check notice on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Runs with UID <= 10000 Low
Check notice on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Runs with GID <= 10000 Low
Check notice on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Runtime/Default Seccomp profile not set Low
Check notice on line 105 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Container capabilities must only include NET_BIND_SERVICE Low
Check notice on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop any Low
Check warning on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
All container images must start with the *.azurecr.io domain Medium
Check warning on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
All container images must start with a GCR domain Medium
Check warning on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Container images from public registries used Medium
Check warning on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
All container images must start with an ECR domain Medium
Check warning on line 107 in mailu/templates/clamav/statefulset.yaml
Code scanning / Trivy
Seccomp policies disabled Medium
Check warning on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Can elevate its own privileges Medium
Check notice on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop all Low
Check notice on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Default capabilities: some containers do not drop any Low
Check warning on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Runs as root user Medium
Check failure on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Root file system is not read-only High
Check notice on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Runs with UID <= 10000 Low
Check notice on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Runs with GID <= 10000 Low
Check failure on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Access to host ports High
Check notice on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
Runtime/Default Seccomp profile not set Low
Check warning on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
All container images must start with the *.azurecr.io domain Medium
Check warning on line 147 in mailu/templates/front/deployment.yaml
Code scanning / Trivy
All container images must start with a GCR domain Medium