Replies: 1 comment
-
|
Hi @jonkerj ! Thanks for the report. Track #9844 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Description
KSV-022 fires if
spec.containers[*].securityContext.capabilities.addcontains anything, while KSV-022 seems to claim that the capabilities should comply with some PodSecurityStandard (unclear which, it says "Capabilities", which is not a default PSS). Assuming this isrestricted,NET_BIND_SERVICEshould be allowed.Desired Behavior
Do not fire if
NET_BIND_SERVICEis addedActual Behavior
KSV-022 fires
Reproduction Steps
Operating System
Talos Linux
Version
`Version: 0.60.0`Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions