Skip to content

Merge pull request #166 from bci-oss/bugfix/fix-security-issues #636

Merge pull request #166 from bci-oss/bugfix/fix-security-issues

Merge pull request #166 from bci-oss/bugfix/fix-security-issues #636

Triggered via push October 10, 2024 11:47
Status Success
Total duration 48s
Artifacts

kics.yml

on: push
Fit to window
Zoom out
Zoom in

Annotations

12 warnings
Analyze
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Analyze
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
[MEDIUM] Container Running With Low UID: charts/bpndiscovery/templates/deployment.yaml#L38
Check if containers are running with low UID, which might cause conflicts with the host's user table.
[MEDIUM] Global Server Object Uses HTTP: backend/src/main/resources/static/bpn-discovery-service-openapi.yaml#L33
Global server object URL should use 'https' protocol instead of 'http'
[MEDIUM] NET_RAW Capabilities Not Being Dropped: charts/bpndiscovery/templates/deployment.yaml#L38
Containers should drop 'ALL' or at least 'NET_RAW' capabilities