Security Scanning & Compliance #59
security-scanning.yml
on: schedule
Matrix: Container Security Scan
Matrix: Infrastructure Security Scan
Code Security Scan
3s
Kubernetes Security Scan
3s
Secrets Scan
16s
Compliance Check
3s
Penetration Testing
0s
Security Policy Enforcement
7s
Generate Security Report
3s
Annotations
54 errors and 16 warnings
Compliance Check
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
Kubernetes Security Scan
Unable to resolve action fairwindsops/polaris-action, repository not found
|
Code Security Scan
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
Security Policy Enforcement
Process completed with exit code 127.
|
Container Security Scan (docker/Dockerfile.ml-training)
Path does not exist: trivy-results-docker/Dockerfile.ml-training.sarif
|
Container Security Scan (docker/Dockerfile.ml-training)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Container Security Scan (docker/Dockerfile.ml-training)
Process completed with exit code 1.
|
Infrastructure Security Scan (gcp)
Resource not accessible by integration
|
Infrastructure Security Scan (gcp)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Infrastructure Security Scan (gcp)
CKV_GCP_111: "Ensure GCP PostgreSQL logs SQL statements"
|
Infrastructure Security Scan (gcp)
CKV_GCP_110: "Ensure pgAudit is enabled for your GCP PostgreSQL database"
|
Infrastructure Security Scan (gcp)
CKV_GCP_79: "Ensure SQL database is using latest Major version"
|
Infrastructure Security Scan (gcp)
CKV_GCP_43: "Ensure KMS encryption keys are rotated within a period of 90 days"
|
Infrastructure Security Scan (gcp)
CKV_GCP_61: "Enable VPC Flow Logs and Intranode Visibility"
|
Infrastructure Security Scan (gcp)
CKV_GCP_13: "Ensure client certificate authentication to Kubernetes Engine Clusters is disabled"
|
Infrastructure Security Scan (gcp)
CKV_GCP_21: "Ensure Kubernetes Clusters are configured with Labels"
|
Infrastructure Security Scan (gcp)
CKV_GCP_69: "Ensure the GKE Metadata Server is Enabled"
|
Infrastructure Security Scan (gcp)
CKV_GCP_65: "Manage Kubernetes RBAC users with Google Groups for GKE"
|
Infrastructure Security Scan (gcp)
CKV_GCP_74: "Ensure that private_ip_google_access is enabled for Subnet"
|
Container Security Scan (docker/Dockerfile.scraping)
Path does not exist: trivy-results-docker/Dockerfile.scraping.sarif
|
Container Security Scan (docker/Dockerfile.scraping)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Container Security Scan (docker/Dockerfile.scraping)
The operation was canceled.
|
Container Security Scan (docker/Dockerfile.scraping)
The strategy configuration was canceled because "container-security-scan.docker_Dockerfile_ml-trai" failed
|
Infrastructure Security Scan (aws)
Resource not accessible by integration
|
Infrastructure Security Scan (aws)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Infrastructure Security Scan (aws)
CKV_AWS_382: "Ensure no security groups allow egress from 0.0.0.0:0 to port -1"
|
Infrastructure Security Scan (aws)
CKV_AWS_23: "Ensure every security group and rule has a description"
|
Infrastructure Security Scan (aws)
CKV_AWS_338: "Ensure CloudWatch log groups retains logs for at least 1 year"
|
Infrastructure Security Scan (aws)
CKV_AWS_158: "Ensure that CloudWatch Log Group is encrypted by KMS"
|
Infrastructure Security Scan (aws)
CKV_AWS_39: "Ensure Amazon EKS public endpoint disabled"
|
Infrastructure Security Scan (aws)
CKV_AWS_38: "Ensure Amazon EKS public endpoint not accessible to 0.0.0.0/0"
|
Infrastructure Security Scan (aws)
CKV_AWS_337: "Ensure SSM parameters are using KMS CMK"
|
Infrastructure Security Scan (aws)
CKV_AWS_337: "Ensure SSM parameters are using KMS CMK"
|
Infrastructure Security Scan (aws)
CKV_AWS_338: "Ensure CloudWatch log groups retains logs for at least 1 year"
|
Infrastructure Security Scan (aws)
CKV_AWS_158: "Ensure that CloudWatch Log Group is encrypted by KMS"
|
Infrastructure Security Scan (aws)
The strategy configuration was canceled because "infrastructure-security-scan.gcp" failed
|
Infrastructure Security Scan (azure)
Resource not accessible by integration
|
Infrastructure Security Scan (azure)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Infrastructure Security Scan (azure)
CKV_AZURE_141: "Ensure AKS local admin account is disabled"
|
Infrastructure Security Scan (azure)
CKV_AZURE_168: "Ensure Azure Kubernetes Cluster (AKS) nodes should use a minimum number of 50 pods."
|
Infrastructure Security Scan (azure)
CKV_AZURE_112: "Ensure that key vault key is backed by HSM"
|
Infrastructure Security Scan (azure)
CKV_AZURE_40: "Ensure that the expiration date is set on all keys"
|
Infrastructure Security Scan (azure)
CKV_AZURE_237: "Ensure dedicated data endpoints are enabled."
|
Infrastructure Security Scan (azure)
CKV_AZURE_165: "Ensure geo-replicated container registries to match multi-region container deployments."
|
Infrastructure Security Scan (azure)
CKV_AZURE_233: "Ensure Azure Container Registry (ACR) is zone redundant"
|
Infrastructure Security Scan (azure)
CKV_AZURE_42: "Ensure the key vault is recoverable"
|
Infrastructure Security Scan (azure)
CKV_AZURE_110: "Ensure that key vault enables purge protection"
|
Infrastructure Security Scan (azure)
CKV_AZURE_160: "Ensure that HTTP (port 80) access is restricted from the internet"
|
Infrastructure Security Scan (azure)
The strategy configuration was canceled because "infrastructure-security-scan.gcp" failed
|
Container Security Scan (docker/Dockerfile.api)
Path does not exist: trivy-results-docker/Dockerfile.api.sarif
|
Container Security Scan (docker/Dockerfile.api)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
|
Container Security Scan (docker/Dockerfile.api)
The operation was canceled.
|
Container Security Scan (docker/Dockerfile.api)
The strategy configuration was canceled because "container-security-scan.docker_Dockerfile_ml-trai" failed
|
Generate Security Report
This request has been automatically failed because it uses a deprecated version of `actions/download-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/. This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
Secrets Scan
🛑 Leaks detected, see job summary for details
|
Container Security Scan (docker/Dockerfile.ml-training)
Resource not accessible by integration
|
Container Security Scan (docker/Dockerfile.ml-training)
Resource not accessible by integration
|
Infrastructure Security Scan (gcp)
Resource not accessible by integration
|
Infrastructure Security Scan (gcp)
Resource not accessible by integration
|
Infrastructure Security Scan (gcp)
Resource not accessible by integration
|
Container Security Scan (docker/Dockerfile.scraping)
Resource not accessible by integration
|
Container Security Scan (docker/Dockerfile.scraping)
Resource not accessible by integration
|
Infrastructure Security Scan (aws)
Resource not accessible by integration
|
Infrastructure Security Scan (aws)
Resource not accessible by integration
|
Infrastructure Security Scan (aws)
Resource not accessible by integration
|
Infrastructure Security Scan (azure)
Resource not accessible by integration
|
Infrastructure Security Scan (azure)
Resource not accessible by integration
|
Infrastructure Security Scan (azure)
Resource not accessible by integration
|
Container Security Scan (docker/Dockerfile.api)
Resource not accessible by integration
|
Container Security Scan (docker/Dockerfile.api)
Resource not accessible by integration
|
Artifacts
Produced during runtime
Name | Size | Digest | |
---|---|---|---|
gitleaks-results.sarif
|
8.3 KB |
sha256:c0e97ed8edcc49b5c284f02c7cc2cd8a8278b1a2644019eb55002294b0eeb597
|
|