Files
OpenShell/.trivyignore.yaml
T
2026-09-14 22:11:42 +00:00

45 lines
1.7 KiB
YAML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# False positives only; unimplemented hardening and accepted risks stay visible.
# The script passes this YAML file explicitly and requires each exception to use
# `**/<concrete-basename>`, which matches source and packaged-chart paths.
# Trivy cannot scope Helm exceptions to one occurrence, so keep IDs and paths
# narrow.
misconfigurations:
# The namespace comes from `helm install -n`, not the rendered workload.
- id: KSV-0110
paths:
- "**/statefulset.yaml"
- "**/deployment.yaml"
statement: >-
An artifact of rendering the chart outside a cluster. The namespace is
supplied at install time.
# The ConfigMap stores an external Secret key name, not a credential.
- id: KSV-01010
paths:
- "**/gateway-config.yaml"
statement: >-
The ConfigMap holds the name of a key in an external Secret, not a
credential.
# Trivy cannot add this project's GHCR namespace to its trusted registries.
- id: KSV-0125
paths:
- "**/statefulset.yaml"
- "**/deployment.yaml"
statement: >-
Images come from ghcr.io/nvidia/openshell, this project's own registry.
# The Kubernetes compute driver creates its runtime infrastructure and the
# per-sandbox outer egress fence in the configured sandbox namespace.
- id: KSV-0056
paths:
- "**/role.yaml"
statement: >-
The namespace-scoped gateway role can create Services and NetworkPolicy
resources so the compute driver can connect each sandbox runtime to its
supervisor while denying direct workload egress.