Prüfen Sie Dockerfiles, GitHub-Actions-Workflows und Kubernetes-Manifeste auf nicht fixierte Images, breite Berechtigungen, privilegierte Konfigurationen und fehlende Runtime-Härtung.
The rules are intentionally conservative. Review every finding against the image, cluster policy, workflow permissions, and environment you actually use.
This local ruleset looks for common practical mistakes, not full policy compliance. Use it alongside image scanning, admission controls, CI policy checks, and your organization’s security review.