Skip to content

Commit 393702c

Browse files
committed
add .semgrep.yml
1 parent a4c2fbf commit 393702c

File tree

2 files changed

+10
-1
lines changed

2 files changed

+10
-1
lines changed

.semgrep.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
rules:
2+
- id: yaml.kubernetes.security.privileged-container.privileged-container
3+
severity: WARNING
4+
languages: [yaml]
5+
patterns:
6+
- pattern: privileged: true
7+
message: "Privileged containers should be avoided."
8+
metadata:
9+
ignore: true

kube_templates/daemonset.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ spec:
1919
image: ghcr.io/firetail-io/kubernetes-sensor:v0.1.5
2020
imagePullPolicy: IfNotPresent
2121
securityContext:
22-
privileged: true # nosemgrep: yaml.kubernetes.security.privileged-container.privileged-container
22+
privileged: true
2323
env:
2424
- name: FIRETAIL_API_URL
2525
value: "https://api.logging.eu-west-1.sandbox.firetail.app/logs/bulk"

0 commit comments

Comments
 (0)