dynatrace-oss / dynatrace-gcp-monitor

Dynatrace integration for Google Cloud Platform monitoring
https://www.dynatrace.com/support/help/technology-support/cloud-platforms/google-cloud-platform/
Apache License 2.0
35 stars 20 forks source link

Two risks found with aqua scanner scanning #393

Closed peijunzh closed 1 year ago

peijunzh commented 1 year ago

With aqua/scanner:2022.4.217 to scan image dynatrace/dynatrace-gcp-monitor:release-1.1.1, there are two risks with actions needed.

image image

Could you please take a look to see if can fix them in next release?

Appreciate!

joaquinfilipic-dynatrace commented 1 year ago

Hello, I'd just mark them as ack. The sensitive data file is an example from the python lib. Regarding the usage of super user, we do have some lines in our scripts to move files only (I don't know what that scanner detected). If you need to dig deeper, please create a ticket and add more details about those scanned risks.