KICS #423
Annotations
1 error and 12 warnings
KICS scan
KICS scan failed with exit code 50
|
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
Upload SARIF file for GitHub Advanced Security Dashboard
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L22
Global security field should be defined to prevent API to have insecure paths and have this rules defined on securitySchemes
|
KICS scan:
build/backend/Dockerfile#L33
A user should be specified in the dockerfile, otherwise the image will run as root
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L798
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1400
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1468
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1198
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1270
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L995
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L215
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L585
All paths should have security scheme, if it is omitted, global security field should be defined
|
Loading