{
  "schemaVersion": "catalog-shared-check-receipt-v1",
  "subject": {
    "id": "prometheus-community-kube-prometheus-stack-87-15-1-existing-secret",
    "chart": "prometheus-community/kube-prometheus-stack",
    "version": "87.15.1",
    "base": "existing-secret",
    "renderPath": "recipes/prometheus-community/kube-prometheus-stack/87.15.1/revisions/existing-secret/r001/rendered/release-objects.yaml",
    "renderFileSHA256": "sha256:7297b2aaced5ed2e6e6bd040af1114b0f4360fa4fdebbb1d63a1ce65d89edfcc"
  },
  "catalogReview": {
    "path": "recipes/prometheus-community/kube-prometheus-stack/87.15.1/revisions/existing-secret/r001/receipts/scan-receipt.yaml",
    "note": "Separate chart-specific Catalog review; not a cub check result."
  },
  "scannerResult": {
    "schema_version": "risk-scan-findings-v1",
    "surface": "cub-scan",
    "finding_count": 25,
    "findings": [
      {
        "id": "CCVE-2025-0043",
        "name": "Thanos sidecar not uploading blocks",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "thanos",
        "resource": {
          "kind": "ServiceMonitor",
          "name": "kube-prometheus-stack-apiserver",
          "namespace": "monitoring"
        },
        "message": "ServiceMonitor selector does not match any Service in target namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Verify Prometheus has --storage.tsdb.min-block-duration=2h and max=2h",
            "Ensure --web.enable-admin-api=true on Prometheus",
            "Check Prometheus external_labels are configured",
            "Verify sidecar has objstore configuration",
            "Wait at least 2 hours after sidecar starts",
            "Check sidecar logs for upload errors"
          ],
          "commands": [
            "kubectl get prometheus -o yaml | grep -A 2 \"storage:\"",
            "kubectl logs -n monitoring -l app.kubernetes.io/component=thanos-sidecar | grep upload",
            "kubectl exec prometheus-xxx -c prometheus -- cat /etc/prometheus/prometheus.yml | grep external_labels"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Verify Prometheus has --storage.tsdb.min-block-duration=2h and max=2h",
          "command": "kubectl get prometheus -o yaml | grep -A 2 \"storage:\"",
          "doc_ref": "cub-scan --explain CCVE-2025-0043"
        }
      },
      {
        "id": "CCVE-2025-0043",
        "name": "Thanos sidecar not uploading blocks",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "thanos",
        "resource": {
          "kind": "ServiceMonitor",
          "name": "kube-prometheus-stack-kubelet",
          "namespace": "monitoring"
        },
        "message": "ServiceMonitor selector does not match any Service in target namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Verify Prometheus has --storage.tsdb.min-block-duration=2h and max=2h",
            "Ensure --web.enable-admin-api=true on Prometheus",
            "Check Prometheus external_labels are configured",
            "Verify sidecar has objstore configuration",
            "Wait at least 2 hours after sidecar starts",
            "Check sidecar logs for upload errors"
          ],
          "commands": [
            "kubectl get prometheus -o yaml | grep -A 2 \"storage:\"",
            "kubectl logs -n monitoring -l app.kubernetes.io/component=thanos-sidecar | grep upload",
            "kubectl exec prometheus-xxx -c prometheus -- cat /etc/prometheus/prometheus.yml | grep external_labels"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Verify Prometheus has --storage.tsdb.min-block-duration=2h and max=2h",
          "command": "kubectl get prometheus -o yaml | grep -A 2 \"storage:\"",
          "doc_ref": "cub-scan --explain CCVE-2025-0043"
        }
      },
      {
        "id": "CCVE-2025-3728",
        "name": "Deployment containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Add resources.limits for memory and CPU to each container",
            "Add resources.requests to enable proper scheduling",
            "Consider LimitRange defaults at the namespace level"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
            "kubectl set resources deployment <name> -n <namespace> --limits=cpu=500m,memory=256Mi --requests=cpu=100m,memory=128Mi"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-WORKLOAD-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Add resources.limits for memory and CPU to each container",
          "command": "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
          "doc_ref": "cub-scan --explain CCVE-2025-3728"
        }
      },
      {
        "id": "CCVE-2025-3728",
        "name": "Deployment containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-kube-state-metrics",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Add resources.limits for memory and CPU to each container",
            "Add resources.requests to enable proper scheduling",
            "Consider LimitRange defaults at the namespace level"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
            "kubectl set resources deployment <name> -n <namespace> --limits=cpu=500m,memory=256Mi --requests=cpu=100m,memory=128Mi"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-WORKLOAD-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Add resources.limits for memory and CPU to each container",
          "command": "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
          "doc_ref": "cub-scan --explain CCVE-2025-3728"
        }
      },
      {
        "id": "CCVE-2025-3728",
        "name": "Deployment containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-operator",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Add resources.limits for memory and CPU to each container",
            "Add resources.requests to enable proper scheduling",
            "Consider LimitRange defaults at the namespace level"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
            "kubectl set resources deployment <name> -n <namespace> --limits=cpu=500m,memory=256Mi --requests=cpu=100m,memory=128Mi"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-WORKLOAD-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Add resources.limits for memory and CPU to each container",
          "command": "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
          "doc_ref": "cub-scan --explain CCVE-2025-3728"
        }
      },
      {
        "id": "CCVE-2025-3732",
        "name": "Deployment containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage",
            "Ensure requests are set when using HPA"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3732"
        }
      },
      {
        "id": "CCVE-2025-3732",
        "name": "Deployment containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-kube-state-metrics",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage",
            "Ensure requests are set when using HPA"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3732"
        }
      },
      {
        "id": "CCVE-2025-3732",
        "name": "Deployment containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-operator",
          "namespace": "monitoring"
        },
        "message": "Deployment containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage",
            "Ensure requests are set when using HPA"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3732"
        }
      },
      {
        "id": "CCVE-2025-3735",
        "name": "Container does not enforce readOnlyRootFilesystem",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Container grafana does not set readOnlyRootFilesystem: true",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set securityContext.readOnlyRootFilesystem to true on every container",
            "Use emptyDir or tmpfs mounts for directories that need write access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].securityContext}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-WORKLOAD-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set securityContext.readOnlyRootFilesystem to true on every container",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].securityContext}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3735"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-kube-state-metrics",
          "namespace": "monitoring"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-operator",
          "namespace": "monitoring"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3745",
        "name": "emptyDir volume has no sizeLimit",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Volume sc-dashboard-volume uses emptyDir without sizeLimit; may exhaust node disk",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set sizeLimit on all emptyDir volumes",
            "Size the limit based on expected usage with headroom",
            "{'Consider using memory-backed emptyDir (medium': 'Memory) for small caches'}"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set sizeLimit on all emptyDir volumes",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3745"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-grafana",
          "namespace": "monitoring"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-kube-state-metrics",
          "namespace": "monitoring"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-operator",
          "namespace": "monitoring"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3756",
        "name": "DaemonSet containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "kube-prometheus-stack-prometheus-node-exporter",
          "namespace": "monitoring"
        },
        "message": "DaemonSet containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.limits.cpu and resources.limits.memory on every container",
            "Size limits based on observed steady-state usage with headroom"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.limits.cpu and resources.limits.memory on every container",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3756"
        }
      },
      {
        "id": "CCVE-2025-3757",
        "name": "DaemonSet containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "DaemonSet",
          "name": "kube-prometheus-stack-prometheus-node-exporter",
          "namespace": "monitoring"
        },
        "message": "DaemonSet containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage"
          ],
          "commands": [
            "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get daemonset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3757"
        }
      },
      {
        "id": "CCVE-2025-4001",
        "name": "CCVE-2025-4001",
        "category": "NETWORKING",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Service",
          "name": "kube-prometheus-stack-alertmanager",
          "namespace": "monitoring"
        },
        "message": "Service selector matches no Deployment or StatefulSet in namespace monitoring",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the Service selector labels match the pod template labels in target Deployment",
            "Run 'kubectl get endpoints <service-name>' to confirm endpoint list is populated"
          ],
          "commands": [
            "kubectl get endpoints <service-name> -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the Service selector labels match the pod template labels in target Deployment",
          "command": "kubectl get endpoints <service-name> -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4001"
        }
      },
      {
        "id": "CCVE-2025-4001",
        "name": "CCVE-2025-4001",
        "category": "NETWORKING",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Service",
          "name": "kube-prometheus-stack-prometheus",
          "namespace": "monitoring"
        },
        "message": "Service selector matches no Deployment or StatefulSet in namespace monitoring",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the Service selector labels match the pod template labels in target Deployment",
            "Run 'kubectl get endpoints <service-name>' to confirm endpoint list is populated"
          ],
          "commands": [
            "kubectl get endpoints <service-name> -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the Service selector labels match the pod template labels in target Deployment",
          "command": "kubectl get endpoints <service-name> -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4001"
        }
      },
      {
        "id": "CCVE-2025-4001",
        "name": "CCVE-2025-4001",
        "category": "NETWORKING",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Service",
          "name": "kube-prometheus-stack-prometheus-node-exporter",
          "namespace": "monitoring"
        },
        "message": "Service selector matches no Deployment or StatefulSet in namespace monitoring",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the Service selector labels match the pod template labels in target Deployment",
            "Run 'kubectl get endpoints <service-name>' to confirm endpoint list is populated"
          ],
          "commands": [
            "kubectl get endpoints <service-name> -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the Service selector labels match the pod template labels in target Deployment",
          "command": "kubectl get endpoints <service-name> -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4001"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "kube-prometheus-stack-operator",
          "namespace": "monitoring"
        },
        "message": "Volume tls-secret references Secret monitoring/kube-prometheus-stack-admission which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "kube-prometheus-stack-grafana-clusterrole",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "kube-prometheus-stack-kube-state-metrics",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "kube-prometheus-stack-operator",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      }
    ],
    "provenance": {
      "source": "cub-scan",
      "source_version": "v0.7.3",
      "scan_time": "2026-08-24T16:00:46Z",
      "catalog_version": "risk-catalog-v1.json@7ff79a126ad9"
    },
    "pattern_bundle": {
      "schema_version": "bundle-manifest-v1",
      "version": "v0.7.3",
      "source_repo": "confighubai/confighub-scan",
      "manifest_sha256": "0405f6ffe21e567adf5d6a732d181c7f228194920456d046b4338baeb14de1a8",
      "catalog_sha256": "7ff79a126ad99bba2505fec8b2b7711c03f50eb362141128ec1c83e27a5036ba"
    },
    "input": {
      "object_count": 124,
      "object_set_sha256": "sha256:f436e8a1b41d478e7201d57c5ca52792cbc1a633a4fe0a9b4fa786e81e08e6f4"
    }
  }
}
