-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Expand file tree
/
Copy path.trivyignore.yaml
More file actions
44 lines (39 loc) · 1.67 KB
/
Copy path.trivyignore.yaml
File metadata and controls
44 lines (39 loc) · 1.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# False positives only; unimplemented hardening and accepted risks stay visible.
# The script passes this YAML file explicitly and requires each exception to use
# `**/<concrete-basename>`, which matches source and packaged-chart paths.
# Trivy cannot scope Helm exceptions to one occurrence, so keep IDs and paths
# narrow.
misconfigurations:
# The namespace comes from `helm install -n`, not the rendered workload.
- id: KSV-0110
paths:
- "**/statefulset.yaml"
- "**/deployment.yaml"
statement: >-
An artifact of rendering the chart outside a cluster. The namespace is
supplied at install time.
# The ConfigMap stores an external Secret key name, not a credential.
- id: KSV-01010
paths:
- "**/gateway-config.yaml"
statement: >-
The ConfigMap holds the name of a key in an external Secret, not a
credential.
# Trivy cannot add this project's GHCR namespace to its trusted registries.
- id: KSV-0125
paths:
- "**/statefulset.yaml"
- "**/deployment.yaml"
statement: >-
Images come from ghcr.io/nvidia/openshell, this project's own registry.
# The Kubernetes compute driver creates its runtime infrastructure and the
# per-sandbox outer egress fence in the configured sandbox namespace.
- id: KSV-0056
paths:
- "**/role.yaml"
statement: >-
The namespace-scoped gateway role can create Services and NetworkPolicy
resources so the compute driver can connect each sandbox runtime to its
supervisor while denying direct workload egress.