Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent CVE-2024-3177 #1007

Draft
wants to merge 21 commits into
base: main
Choose a base branch
from
Draft
Changes from 1 commit
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
8eeff43
create policy and artifact-pkg
May 14, 2024
97c03e0
make sure we are in Audit mode
May 14, 2024
f0b2ee4
add a date to artifact hub
May 14, 2024
99948ec
Merge branch 'kyverno:main' into secrets-not-from-env-vars-cve-2024-3177
kurktchiev Jun 11, 2024
f980aad
Merge branch 'kyverno:main' into secrets-not-from-env-vars-cve-2024-3177
kurktchiev Jul 23, 2024
e4a8eff
Merge branch 'main' into secrets-not-from-env-vars-cve-2024-3177
kurktchiev Jul 29, 2024
901a4ab
add good and bad objects
Jul 29, 2024
da3cc80
add kube version
Jul 29, 2024
127938f
Update other/secrets-not-from-env-vars-cve-2024-3177/secrets-not-from…
kurktchiev Jul 31, 2024
aa97eb2
Update other/secrets-not-from-env-vars-cve-2024-3177/secrets-not-from…
kurktchiev Jul 31, 2024
d2bc6b3
Update other/secrets-not-from-env-vars-cve-2024-3177/artifacthub-pkg.yml
kurktchiev Jul 31, 2024
1f6690e
Update other/secrets-not-from-env-vars-cve-2024-3177/artifacthub-pkg.yml
kurktchiev Jul 31, 2024
e6b2b27
Update other/secrets-not-from-env-vars-cve-2024-3177/artifacthub-pkg.yml
kurktchiev Jul 31, 2024
55366ac
Merge branch 'main' into secrets-not-from-env-vars-cve-2024-3177
kurktchiev Jul 31, 2024
4cddd5f
Update other/secrets-not-from-env-vars-cve-2024-3177/artifacthub-pkg.yml
kurktchiev Jul 31, 2024
3377269
Update other/secrets-not-from-env-vars-cve-2024-3177/secrets-not-from…
kurktchiev Jul 31, 2024
73f9875
updat edescription
Jul 31, 2024
657be9a
fix suggestions
Jul 31, 2024
203e2f1
update digest
Jul 31, 2024
46ea9ed
Merge branch 'main' into secrets-not-from-env-vars-cve-2024-3177
kurktchiev Aug 6, 2024
6876562
add tests
Aug 6, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Update other/secrets-not-from-env-vars-cve-2024-3177/artifacthub-pkg.yml
Co-authored-by: Chip Zoller <chipzoller@gmail.com>
Signed-off-by: Boris 'B' Kurktchiev <kurktchiev@gmail.com>
kurktchiev and chipzoller authored Jul 31, 2024
commit d2bc6b3523689cfbc803df44177ed893f9991932
Original file line number Diff line number Diff line change
@@ -14,7 +14,7 @@ keywords:
readme: |
Secrets used as environment variables containing sensitive information may, if not carefully controlled, be printed in log output which could be visible to unauthorized people and captured in forwarding applications. This policy specifically blocks CVE-2024-3177
annotations:
kyverno/category: "Other"
kyverno/category: "Security"
kyverno/kubernetesVersion: "1.29"
kyverno/subject: "Deployment"
digest: 80c2bc5cbe9081ae7ca6598f8ef435467bb487818df49a6b4c95e35f442be0e2