Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

metaphor-frontend Argo CD GitHub Action does not have any security context set #1023

Open
fharper opened this issue Dec 29, 2022 · 0 comments
Labels
good first issue Good for newcomers security Anything security related

Comments

@fharper
Copy link
Member

fharper commented Dec 29, 2022

metaphor-frontend Argo CD GitHub Action does not have any security context set. It's probably the case for any metaphor app, not just frontend.

This workflow does not have security context set. You can run your workflow pods more securely by setting it.

Maybe there's a reason that we need to run it as root (even in that case, we may not need all permissions), but security-wise, make more sense to not do this. See how to set up security context.

P.S.: I may miss Kubefirst with Argo CD context,

@fharper fharper added enhancement security Anything security related labels Dec 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers security Anything security related
Projects
Status: No status
Development

No branches or pull requests

2 participants