KICS #426
Annotations
1 error and 12 warnings
KICS scan
KICS scan failed with exit code 50
|
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
Upload SARIF file for GitHub Advanced Security Dashboard
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L22
Global security field should be defined to prevent API to have insecure paths and have this rules defined on securitySchemes
|
KICS scan:
build/backend/Dockerfile#L33
A user should be specified in the dockerfile, otherwise the image will run as root
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1227
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1052
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L1370
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L596
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L186
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L109
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L537
All paths should have security scheme, if it is omitted, global security field should be defined
|
KICS scan:
demand-capacity-mgmt-specification/src/main/resources/openapi.yml#L611
All paths should have security scheme, if it is omitted, global security field should be defined
|
Loading