Identified Risks

This table shows all the identified risks for this repository.

Filename
Message
Scanner
Dockerfile
Ensure that a user for the container has been created
iac
Dockerfile
Ensure that HEALTHCHECK instructions have been added to container images
iac
/builds/l3montree/devguard/Dockerfile
By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'.
sast
images/Dockerfile.kaniko-crane
Ensure that a user for the container has been created
iac
images/Dockerfile.kaniko-crane
Ensure that HEALTHCHECK instructions have been added to container images
iac

Showing 1 of 1 pages (5 items)

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version d51ba4d3f2ef56cdcc49e35bed410d86e1263d7a