External Scan Lane

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This lane runs a market-standard rendered-manifest scanner against the exact supported top-20 rendered object sets.

It is additive to the existing local scan/gate receipts. It does not replace ConfigHub function checks or chart-specific production dispositions.

Tool Status

ToolAvailableVersion
kube-linteryes0.8.3
TrivyyesVersion: 0.71.1
kubeconformnon/a

Summary

charts scanned: 20
variant rendered object sets scanned: 42
pass: 0
warn: 42
fail: 0
total findings: 320

Most Common Findings

CheckCount
unset-memory-requirements93
unset-cpu-requirements87
no-read-only-root-fs43
dangling-service20
pdb-unhealthy-pod-eviction-policy16
run-as-non-root16
sensitive-host-mounts9
liveness-port8
readiness-port8
startup-port5
privilege-escalation-container4
privileged-container4

Chart Workdown

The chart workdown groups variant findings into the next production action. Use it with production-disposition when closing scan/gate warning disposition.

ChartVariantsFindingsPriorityTop checksNext action
prometheus-community/kube-prometheus-stack@85.3.3254highdangling-service:14;unset-cpu-requirements:12;unset-memory-requirements:12;no-read-only-root-fs:6;sensitive-host-mounts:6;host-network:2;host-pid:2record security acceptance or create a hardened base; review service selectors and runtime endpoints; add production resource policy or accept chart defaults for local-test only; review pod security posture for the production target
longhorn/longhorn@1.11.2248highno-read-only-root-fs:10;run-as-non-root:10;unset-cpu-requirements:10;unset-memory-requirements:10;dangling-service:4;privilege-escalation-container:2;privileged-container:2record security acceptance or create a hardened base; review service selectors and runtime endpoints; add production resource policy or accept chart defaults for local-test only; review pod security posture for the production target
prometheus-community/prometheus@29.8.0227highunset-cpu-requirements:8;unset-memory-requirements:8;no-read-only-root-fs:6;sensitive-host-mounts:3;host-network:1;host-pid:1record security acceptance or create a hardened base; add production resource policy or accept chart defaults for local-test only; review pod security posture for the production target
secrets-store-csi-driver/secrets-store-csi-driver@1.6.0216highno-read-only-root-fs:6;run-as-non-root:6;privilege-escalation-container:2;privileged-container:2record security acceptance or create a hardened base; review pod security posture for the production target
bitnami/nginx@24.0.222standardpdb-unhealthy-pod-eviction-policy:2accept PDB behavior or add a reviewed patch where the chart supports it

Interpretation

warn means the external scanner found issues that must receive a production disposition before catalog production support is claimed. The rendered digest is recorded per row, so each scanner result is bound to the exact objects we would publish or install.