Skip to content

misconf: Revise KSV-0022 to allow valid capabilities#552

Open
mattcarp12 wants to merge 2 commits intoaquasecurity:mainfrom
mattcarp12:fix/ksv022-allow-baseline-capabilities
Open

misconf: Revise KSV-0022 to allow valid capabilities#552
mattcarp12 wants to merge 2 commits intoaquasecurity:mainfrom
mattcarp12:fix/ksv022-allow-baseline-capabilities

Conversation

@mattcarp12
Copy link
Copy Markdown

Currently, the KSV-0022 check flags all added capabilities, even those allowed by the Pod Security Standard, such as NET_BIND_SERVICE. We need to review and update this check to ensure it aligns with compliance requirements, allows valid capabilities, and provides a clearer, more informative message that specifies which capabilities are causing violations.

Closes: aquasecurity/trivy#9844

@mattcarp12
Copy link
Copy Markdown
Author

@simar7 @nikpivkin Can you please look at this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

misconf: Revise KSV-0022 to allow valid capabilities

1 participant