-
Notifications
You must be signed in to change notification settings - Fork 29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Modify rule S6868: Make S6868 a Security Hotspot #4340
Modify rule S6868: Make S6868 a Security Hotspot #4340
Conversation
Quality Gate passed for 'rspec-tools'Issues Measures |
Quality Gate passed for 'rspec-frontend'Issues Measures |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Minor: Moving a sentence from a place to another
rules/S6868/kubernetes/rule.adoc
Outdated
@@ -55,27 +45,14 @@ rules: | |||
verbs: ["get"] | |||
---- | |||
|
|||
=== How does this work? | |||
|
|||
The `exec` permissions are set by allowing the `create` verb for the `pods/exec` resource. Removing this permission will prevent users and services from executing arbitrary commands within containers. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This sentence is lonely here, I suggest adding moving it from here to the "recommended secure practices"
406f9b9
to
9d50a77
Compare
Quality Gate passed for 'rspec-tools'Issues Measures |
Quality Gate passed for 'rspec-frontend'Issues Measures |
The `exec` permissions are set by allowing the `create` verb for the `pods/exec` resource. | ||
Removing this permission will prevent users and services from executing arbitrary commands within containers. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added here according to Loris suggestions
Review
A dedicated reviewer checked the rule description successfully for: