Closed wojiushixiaobai closed 8 months ago
code | level | alerts | |
---|---|---|---|
0 | CIS-DI-0001 | WARN | Last user should not be root |
1 | CIS-DI-0005 | INFO | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
2 | CIS-DI-0006 | INFO | not found HEALTHCHECK statement |
3 | CIS-DI-0008 | INFO | setuid file: urwxr-xr-x usr/bin/gpasswd |
[
"cr.loongnix.cn/prometheus/busybox:glibc",
"cr.loongnix.cn/kubevirt/passwd:0.50.0",
"cr.loongnix.cn/library/haproxy:2.3",
"cr.loongnix.cn/library/ruby:2.5.5",
"cr.loongnix.cn/library/spiped:1.6",
"cr.loongnix.cn/library/python:3.9",
"cr.loongnix.cn/library/python:3.12",
"cr.loongnix.cn/library/python:3.7.10",
"cr.loongnix.cn/library/node:18.13.0-debian",
"cr.loongnix.cn/library/postgres:13.13-debian",
"cr.loongnix.cn/library/redis:7.2",
"cr.loongnix.cn/library/python:3.10",
"cr.loongnix.cn/library/python:3.11",
"cr.loongnix.cn/library/node:20.8.0-debian",
"cr.loongnix.cn/library/caddy:debian",
"cr.loongnix.cn/library/openjdk:8-buster",
"cr.loongnix.cn/library/openjdk:21-buster",
"cr.loongnix.cn/library/openjdk:17-buster",
"cr.loongnix.cn/library/openjdk:11-buster",
"cr.loongnix.cn/minio/mc:debian",
"cr.loongnix.cn/minio/minio:debian",
"cr.loongnix.cn/library/redis:7.0",
"cr.loongnix.cn/library/redis:6.0",
"cr.loongnix.cn/library/redis:6.2",
"cr.loongnix.cn/library/mariadb:10.6",
"cr.loongnix.cn/library/mariadb:10.11"
]
@zhaixiaojuan @znley
code | level | alerts | |
---|---|---|---|
0 | CIS-DI-0001 | WARN | Last user should not be root |
1 | CIS-DI-0005 | INFO | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
2 | CIS-DI-0006 | INFO | not found HEALTHCHECK statement |
3 | CIS-DI-0008 | INFO | setuid file: urwxr-xr-x usr/bin/passwd |
[
"cr.loongnix.cn/prometheus/busybox:glibc",
"cr.loongnix.cn/kubevirt/passwd:0.50.0",
"cr.loongnix.cn/library/haproxy:2.3",
"cr.loongnix.cn/library/ruby:2.5.5",
"cr.loongnix.cn/library/spiped:1.6",
"cr.loongnix.cn/library/python:3.9",
"cr.loongnix.cn/library/python:3.12",
"cr.loongnix.cn/library/python:3.7.10",
"cr.loongnix.cn/library/node:18.13.0-debian",
"cr.loongnix.cn/library/postgres:13.13-debian",
"cr.loongnix.cn/library/redis:7.2",
"cr.loongnix.cn/library/python:3.10",
"cr.loongnix.cn/library/python:3.11",
"cr.loongnix.cn/library/node:20.8.0-debian",
"cr.loongnix.cn/library/caddy:debian",
"cr.loongnix.cn/library/openjdk:8-buster",
"cr.loongnix.cn/library/openjdk:21-buster",
"cr.loongnix.cn/library/openjdk:17-buster",
"cr.loongnix.cn/library/openjdk:11-buster",
"cr.loongnix.cn/minio/mc:debian",
"cr.loongnix.cn/minio/minio:debian",
"cr.loongnix.cn/library/redis:7.0",
"cr.loongnix.cn/library/redis:6.0",
"cr.loongnix.cn/library/redis:6.2",
"cr.loongnix.cn/library/mariadb:10.6",
"cr.loongnix.cn/library/mariadb:10.11"
]
@zhaixiaojuan @znley
systemd-journal
占用了nginx
的gid
,需要移除。