From c0732e94566a9c53f908e65ac22d640525bf0ec7 Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Thu, 20 Mar 2025 19:13:00 +0000 Subject: [PATCH] fix(security): autofix Container running as root can allow attacker to escalate attacks - KAN-412 --- busybox.yaml | 2 ++ insecure-app.yaml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/busybox.yaml b/busybox.yaml index 0d24d74..dbbf501 100644 --- a/busybox.yaml +++ b/busybox.yaml @@ -14,6 +14,8 @@ spec: labels: app: busybox spec: + securityContext: + runAsNonRoot: true containers: - name: busybox image: busybox diff --git a/insecure-app.yaml b/insecure-app.yaml index 93339aa..4974ead 100644 --- a/insecure-app.yaml +++ b/insecure-app.yaml @@ -14,6 +14,8 @@ spec: labels: app: insecure-app spec: + securityContext: + runAsNonRoot: true containers: - image: confusedcrib/insecure-app:latest name: insecure-app