forked from jaydenaung/kubesentinel
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathNOTICE
More file actions
111 lines (89 loc) · 3.65 KB
/
Copy pathNOTICE
File metadata and controls
111 lines (89 loc) · 3.65 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
KubeSentinel — AI-Powered Kubernetes Security Platform
Copyright 2026 Jayden Aung
Licensed under the Apache License, Version 2.0.
See LICENSE for the full license text.
-------------------------------------------------------------------------------
THIRD-PARTY SOFTWARE AND TOOLS
-------------------------------------------------------------------------------
This product bundles or integrates the following third-party software.
Each component is governed by its own license as noted below.
-------------------------------------------------------------------------------
Trivy
Copyright (c) 2019 Aqua Security Software Ltd.
License: Apache License 2.0
Source: https://github.com/aquasecurity/trivy
Use: Container image and filesystem vulnerability scanning (CVE detection).
kubectl
Copyright (c) The Kubernetes Authors
License: Apache License 2.0
Source: https://github.com/kubernetes/kubectl
Use: Live cluster interrogation and ServiceAccount permission probing.
Helm
Copyright (c) The Helm Authors
License: Apache License 2.0
Source: https://github.com/helm/helm
Use: Helm chart rendering (helm template) before manifest analysis.
-------------------------------------------------------------------------------
PYTHON DEPENDENCIES
-------------------------------------------------------------------------------
anthropic (Anthropic SDK)
Copyright (c) Anthropic, PBC
License: MIT
Source: https://github.com/anthropic/anthropic-sdk-python
Use: Claude API integration for agentic scanning, AI enrichment, and patch generation.
FastAPI
Copyright (c) Sebastián Ramírez
License: MIT
Source: https://github.com/tiangolo/fastapi
Use: Web framework for the KubeSentinel dashboard.
SQLAlchemy
Copyright (c) SQLAlchemy authors
License: MIT
Source: https://github.com/sqlalchemy/sqlalchemy
Use: ORM for scan history, findings, and compliance results persistence.
Uvicorn
Copyright (c) Encode OSS Ltd.
License: BSD 3-Clause
Source: https://github.com/encode/uvicorn
Use: ASGI server for the FastAPI web application.
Jinja2
Copyright (c) Armin Ronacher and contributors
License: BSD 3-Clause
Source: https://github.com/pallets/jinja
Use: HTML templating for the web dashboard.
APScheduler
Copyright (c) Alex Grönholm
License: MIT
Source: https://github.com/agronholm/apscheduler
Use: Scheduled recurring cluster scans.
PyYAML
Copyright (c) Kirill Simonov
License: MIT
Source: https://github.com/yaml/pyyaml
Use: YAML manifest parsing.
bcrypt
Copyright (c) The Python bcrypt contributors
License: Apache License 2.0
Source: https://github.com/pyca/bcrypt
Use: Password hashing for user authentication.
python-dotenv
Copyright (c) Saurabh Kumar
License: BSD 3-Clause
Source: https://github.com/theskumar/python-dotenv
Use: Loading environment variables from .env files.
itsdangerous
Copyright (c) Armin Ronacher and contributors
License: BSD 3-Clause
Source: https://github.com/pallets/itsdangerous
Use: Secure session cookie signing.
-------------------------------------------------------------------------------
ACKNOWLEDGEMENTS
-------------------------------------------------------------------------------
KubeSentinel's security checks are informed by the following frameworks
and publications:
- CIS Kubernetes Benchmark (Center for Internet Security)
https://www.cisecurity.org/benchmark/kubernetes
- NSA/CISA Kubernetes Hardening Guidance
https://media.defense.gov/2022/Aug/29/2003066362/-1/-1/0/CTR_KUBERNETES_HARDENING_GUIDANCE_1.2_20220829.PDF
- OWASP Kubernetes Top 10
https://owasp.org/www-project-kubernetes-top-ten/