Open ariyonaty opened 1 month ago
Attention: Patch coverage is 52.38095%
with 10 lines
in your changes missing coverage. Please review.
Project coverage is 62.34%. Comparing base (
dbd7529
) to head (6331670
). Report is 29 commits behind head on main.
Files | Patch % | Lines |
---|---|---|
pkg/templates/runasnonroot/template.go | 52.38% | 10 Missing :warning: |
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
Closes #748
This PR introduces changes which expand the
run-as-non-root
template/check to verifyrunAsGroup
field is set to a non-zero value.The
runAsGroup
field specifies the group ID under which the container’s process should run. If left unspecified, the GID defaults to 0.Snippet of build in action where
pod.yaml
for first execution initially didn't setrunAsGroup
, second execution set the field to 0, and finally set to a non-zero value: