mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2025-03-05 01:26:18 +00:00
fix: typo of applicaions which should have been applications (#1819)
This commit is contained in:
parent
949999145e
commit
c40b2a72e2
@ -132,7 +132,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications runnning on your cluster. Where a namespace
|
Review the use of capabilites in applications runnning on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -443,7 +443,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -146,7 +146,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -132,7 +132,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -132,7 +132,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -188,7 +188,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -188,7 +188,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -289,7 +289,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -184,7 +184,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider
|
contains applications which do not require any Linux capabities to operate consider
|
||||||
adding a SCC which forbids the admission of containers which do not drop all capabilities.
|
adding a SCC which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -193,7 +193,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -191,7 +191,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -153,7 +153,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -188,7 +188,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
scored: false
|
scored: false
|
||||||
|
|
||||||
|
@ -160,7 +160,7 @@ groups:
|
|||||||
type: "manual"
|
type: "manual"
|
||||||
remediation: |
|
remediation: |
|
||||||
Review the use of capabilites in applications running on your cluster. Where a namespace
|
Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
Exception
|
Exception
|
||||||
This is site-specific setting.
|
This is site-specific setting.
|
||||||
|
2
integration/testdata/Expected_output.data
vendored
2
integration/testdata/Expected_output.data
vendored
@ -385,7 +385,7 @@ UIDs not including 0.
|
|||||||
it is set to an empty array.
|
it is set to an empty array.
|
||||||
|
|
||||||
5.2.9 Review the use of capabilites in applications running on your cluster. Where a namespace
|
5.2.9 Review the use of capabilites in applications running on your cluster. Where a namespace
|
||||||
contains applicaions which do not require any Linux capabities to operate consider adding
|
contains applications which do not require any Linux capabities to operate consider adding
|
||||||
a PSP which forbids the admission of containers which do not drop all capabilities.
|
a PSP which forbids the admission of containers which do not drop all capabilities.
|
||||||
|
|
||||||
5.3.1 If the CNI plugin in use does not support network policies, consideration should be given to
|
5.3.1 If the CNI plugin in use does not support network policies, consideration should be given to
|
||||||
|
Loading…
Reference in New Issue
Block a user