apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "ScanReceipt"
metadata:
  labels:
    confighub.io/chart-ref: "argo-cd/argo-workflows"
    confighub.io/chart-version: "1.0.14"
    confighub.io/proof-tier: "next80-full"
    confighub.io/variant: "controller-default-reviewed"
  name: "argo-cd-argo-workflows-1-0-14-controller-default-reviewed-r001"
spec:
  findingCounts:
    critical: 0
    high: 0
    info: 0
    low: 0
    medium: 11
  findings:
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-admin"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-admin"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-edit"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-edit"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-server"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-server"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-server-cluster-template"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-server-cluster-template"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-view"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-view"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-workflow-controller"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-workflow-controller"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-workflow-controller-cluster-template"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRole||argo-workflows-workflow-controller-cluster-template"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-server"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-server"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-server-cluster-template"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-server-cluster-template"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-workflow-controller"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-workflow-controller"
      rule: "cluster-rbac-review"
      severity: "medium"
    -
      id: "cluster-rbac-review:rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-workflow-controller-cluster-template"
      message: "Cluster-scoped RBAC requires production review"
      object: "rbac.authorization.k8s.io/v1|ClusterRoleBinding||argo-workflows-workflow-controller-cluster-template"
      rule: "cluster-rbac-review"
      severity: "medium"
  policyBundleDigest: "d4913c44f60cee40b376761c82c0c5b84e3f65043012ae875d8f376330dabc35"
  renderedObjectSetSHA256: "677516f7d311ffdfcf7a4b424585cada43ba104af51ef7e283c575d8279c16bc"
  result: "warn"
  scanner:
    name: "helm-expt-local-rendered-object-scan"
    version: "0.2.0"
  variantRevision: "../variant-revision.yaml"
  usefulBaseAlias:
    sourceBase: "default"
    realizationStrategy: "alias-of-default-render"
