{
  "schemaVersion": "catalog-shared-check-receipt-v1",
  "subject": {
    "id": "vm-victoria-metrics-single-0-39-0-default-reviewed",
    "chart": "vm/victoria-metrics-single",
    "version": "0.39.0",
    "base": "default-reviewed",
    "renderPath": "recipes/vm/victoria-metrics-single/0.39.0/revisions/default-reviewed/r001/rendered/release-objects.yaml",
    "renderFileSHA256": "sha256:10c95bd43cb02502fb823b0d461c26b60fb0b4fe988ccf8a0cbe2e29f0a8c5f8"
  },
  "catalogReview": {
    "path": "recipes/vm/victoria-metrics-single/0.39.0/revisions/default-reviewed/r001/receipts/scan-receipt.yaml",
    "note": "Separate chart-specific Catalog review; not a cub check result."
  },
  "scannerResult": {
    "schema_version": "risk-scan-findings-v1",
    "surface": "cub-scan",
    "finding_count": 6,
    "findings": [
      {
        "id": "CCVE-2025-3747",
        "name": "StatefulSet missing security context",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "StatefulSet omits pod and container securityContext settings",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set securityContext at pod and container level",
            "Enforce runAsNonRoot, readOnlyRootFilesystem, and drop ALL capabilities",
            "Apply a seccomp profile (RuntimeDefault or stricter)"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set securityContext at pod and container level",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3747"
        }
      },
      {
        "id": "CCVE-2025-3748",
        "name": "StatefulSet container does not set runAsNonRoot",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "Container vmsingle does not set runAsNonRoot: true",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set securityContext.runAsNonRoot to true at pod or container level",
            "Set runAsUser to a non-zero UID",
            "Ensure container images do not require root"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set securityContext.runAsNonRoot to true at pod or container level",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.securityContext}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3748"
        }
      },
      {
        "id": "CCVE-2025-3749",
        "name": "StatefulSet containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "StatefulSet containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.limits.cpu and resources.limits.memory on every container",
            "Align limits with observed peak usage plus headroom",
            "Consider LimitRange policies as a cluster-level safety net"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.limits.cpu and resources.limits.memory on every container",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3749"
        }
      },
      {
        "id": "CCVE-2025-3750",
        "name": "StatefulSet containers omit resource requests",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "StatefulSet containers omit resource requests; HPA and scheduler decisions will be unreliable",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set resources.requests.cpu and resources.requests.memory on every container",
            "Align requests with observed steady-state usage",
            "Ensure requests are set when using HPA"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set resources.requests.cpu and resources.requests.memory on every container",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.containers[*].resources}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3750"
        }
      },
      {
        "id": "CCVE-2025-3752",
        "name": "StatefulSet does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "StatefulSet does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3752"
        }
      },
      {
        "id": "CCVE-2025-5013",
        "name": "Helm-managed StatefulSet may orphan PVCs on release lifecycle operations",
        "category": "ORPHAN",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "medium",
        "tool": "helm",
        "resource": {
          "kind": "StatefulSet",
          "name": "victoria-metrics-single-server",
          "namespace": "default"
        },
        "message": "Helm-managed StatefulSet with volumeClaimTemplates is missing Delete/Delete PVC retention policy and can orphan storage on release lifecycle operations",
        "remedy_type": "config_fix",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Set persistentVolumeClaimRetentionPolicy to Delete/Delete for ephemeral lifecycle expectations",
            "Document explicit PVC retention and cleanup procedures when Retain is intentional",
            "Add release cleanup automation for orphaned PVCs if data retention is not required"
          ],
          "commands": [
            "kubectl get sts -n <namespace> <name> -o yaml",
            "kubectl get pvc -n <namespace> -l app.kubernetes.io/instance=<release>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Set persistentVolumeClaimRetentionPolicy to Delete/Delete for ephemeral lifecycle expectations",
          "command": "kubectl get sts -n <namespace> <name> -o yaml",
          "doc_ref": "cub-scan --explain CCVE-2025-5013"
        }
      }
    ],
    "provenance": {
      "source": "cub-scan",
      "source_version": "v0.7.3",
      "scan_time": "2026-08-24T16:00:53Z",
      "catalog_version": "risk-catalog-v1.json@7ff79a126ad9"
    },
    "pattern_bundle": {
      "schema_version": "bundle-manifest-v1",
      "version": "v0.7.3",
      "source_repo": "confighubai/confighub-scan",
      "manifest_sha256": "0405f6ffe21e567adf5d6a732d181c7f228194920456d046b4338baeb14de1a8",
      "catalog_sha256": "7ff79a126ad99bba2505fec8b2b7711c03f50eb362141128ec1c83e27a5036ba"
    },
    "input": {
      "object_count": 3,
      "object_set_sha256": "sha256:ba86383170c8b32ade9c4def56f7469749b62608dba351566143d17d4197c65c"
    }
  }
}
