Skip to content

model-metadata-collection: Security

Secrets

Kubernetes secrets referenced by this component. Only names and types are shown, not values.

Deployment Security Controls

SecurityContext settings on pod and container specs. These control privilege escalation, filesystem access, and user identity.

Build Security

Dockerfile patterns and base image analysis. Covers supply chain security: base images, build stages, runtime user, FIPS compliance.

Path Base Image Stages User Ports Architectures FIPS Issues
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/Dockerfile alpine:${ALPINE_VERSION} 8 multi-arch Unpinned base image: base; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: base; Unpinned base image: scratch; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/contrib/compose/nginx/Dockerfile nginx:1.7 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/Dockerfile distribution/golem:0.1 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/nginx/Dockerfile nginx:1.9 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/tokenserver-oauth/Dockerfile dmcgowan/token-server@sha256:5a6f76d3086cdf63249c77b521108387b49d85a30c5e1c4fe82fdf5ae3b76ba7 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/tokenserver/Dockerfile dmcgowan/token-server@sha256:0eab50ebdff5b6b95b3addf4edbd8bd2f5b940f27b41b43c94afdf05863a81af 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/distribution@v2.8.3+incompatible/project/dev-image/Dockerfile ubuntu:14.04 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker-credential-helpers@v0.9.3/Dockerfile binaries 20 multi-arch Unpinned base image: gobase; Unpinned base image: scratch; Unpinned base image: vendored; Unpinned base image: gobase; Unpinned base image: gobase; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: gobase; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: build-$TARGETOS; Unpinned base image: scratch; Unpinned base image: alpine; Unpinned base image: scratch; Unpinned base image: binaries; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker-credential-helpers@v0.9.3/deb/Dockerfile ${DISTRO}:${SUITE} 2 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/Dockerfile dev-base 71 multi-arch Unpinned base image: busybox; Unpinned base image: scratch; Unpinned base image: ${GOLANG_IMAGE}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: binary-dummy; Unpinned base image: delve-${DELVE_SUPPORTED}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: containerd-build; Unpinned base image: binary-dummy; Unpinned base image: containerd-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: runc-build; Unpinned base image: binary-dummy; Unpinned base image: runc-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: tini-build; Unpinned base image: binary-dummy; Unpinned base image: tini-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: rootlesskit-build; Unpinned base image: binary-dummy; Unpinned base image: rootlesskit-${TARGETOS}; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: vpnkit-linux-${TARGETARCH}; Unpinned base image: vpnkit-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: binary-dummy; Unpinned base image: containerutil-build; Unpinned base image: containerutil-windows-${TARGETARCH}; Unpinned base image: containerutil-${TARGETOS}; Unpinned base image: base; Unpinned base image: dev-systemd-false; Unpinned base image: dev-systemd-${SYSTEMD}; Unpinned base image: dev-systemd-true; Unpinned base image: dev-firewalld-${FIREWALLD}; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: base; Unpinned base image: dev-base; Unpinned base image: dev-base; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/Dockerfile.simple ${GOLANG_IMAGE} 1 Unpinned base image: ${GOLANG_IMAGE}; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/Dockerfile.windows ${WINDOWS_BASE_IMAGE}:${WINDOWS_BASE_IMAGE_TAG} 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/busybox/Dockerfile ${WINDOWS_BASE_IMAGE}:${WINDOWS_BASE_IMAGE_TAG} 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/httpserver/Dockerfile busybox 1 Unpinned base image: busybox; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/nnp-test/Dockerfile debian:bookworm-slim 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/nano/Dockerfile.nanorc 0 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/textmate/Docker.tmbundle/Preferences/Dockerfile.tmPreferences 0 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/textmate/Docker.tmbundle/Syntaxes/Dockerfile.tmLanguage 0 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/contrib/syscall-test/Dockerfile debian:bookworm-slim 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/diagnostic/Dockerfile.client alpine 1 Unpinned base image: alpine; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/diagnostic/Dockerfile.dind docker:17.12-dind 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/networkdb-test/Dockerfile alpine 1 Unpinned base image: alpine; No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/ssd/Dockerfile alpine:3.7 1 No USER directive found (defaults to root)
.gomod-cache/github.com/docker/docker@v28.3.3+incompatible/libnetwork/support/Dockerfile docker:18-dind 1 No USER directive found (defaults to root)
.gomod-cache/golang.org/toolchain@v0.0.1-go1.25.7.linux-amd64/src/crypto/internal/boring/Dockerfile $ubuntu:focal 1 No USER directive found (defaults to root)
.gomod-cache/golang.org/toolchain@v0.0.1-go1.25.7.linux-amd64/src/crypto/internal/fips140/nistec/fiat/Dockerfile coqorg/coq:8.13.2 1 No USER directive found (defaults to root)
.gomod-cache/golang.org/x/sys@v0.35.0/unix/linux/Dockerfile ubuntu:24.10 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/Dockerfile alpine:${ALPINE_VERSION} 8 multi-arch Unpinned base image: base; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: base; Unpinned base image: scratch; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/contrib/compose/nginx/Dockerfile nginx:1.7 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/Dockerfile distribution/golem:0.1 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/nginx/Dockerfile nginx:1.9 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/tokenserver-oauth/Dockerfile dmcgowan/token-server@sha256:5a6f76d3086cdf63249c77b521108387b49d85a30c5e1c4fe82fdf5ae3b76ba7 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/contrib/docker-integration/tokenserver/Dockerfile dmcgowan/token-server@sha256:0eab50ebdff5b6b95b3addf4edbd8bd2f5b940f27b41b43c94afdf05863a81af 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/distribution@v2.8.3+incompatible/project/dev-image/Dockerfile ubuntu:14.04 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker-credential-helpers@v0.9.3/Dockerfile binaries 20 multi-arch Unpinned base image: gobase; Unpinned base image: scratch; Unpinned base image: vendored; Unpinned base image: gobase; Unpinned base image: gobase; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: gobase; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: build-$TARGETOS; Unpinned base image: scratch; Unpinned base image: alpine; Unpinned base image: scratch; Unpinned base image: binaries; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker-credential-helpers@v0.9.3/deb/Dockerfile ${DISTRO}:${SUITE} 2 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/Dockerfile dev-base 71 multi-arch Unpinned base image: busybox; Unpinned base image: scratch; Unpinned base image: ${GOLANG_IMAGE}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: binary-dummy; Unpinned base image: delve-${DELVE_SUPPORTED}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: containerd-build; Unpinned base image: binary-dummy; Unpinned base image: containerd-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: base; Unpinned base image: runc-build; Unpinned base image: binary-dummy; Unpinned base image: runc-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: tini-build; Unpinned base image: binary-dummy; Unpinned base image: tini-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: rootlesskit-build; Unpinned base image: binary-dummy; Unpinned base image: rootlesskit-${TARGETOS}; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: vpnkit-linux-${TARGETARCH}; Unpinned base image: vpnkit-${TARGETOS}; Unpinned base image: base; Unpinned base image: base; Unpinned base image: binary-dummy; Unpinned base image: containerutil-build; Unpinned base image: containerutil-windows-${TARGETARCH}; Unpinned base image: containerutil-${TARGETOS}; Unpinned base image: base; Unpinned base image: dev-systemd-false; Unpinned base image: dev-systemd-${SYSTEMD}; Unpinned base image: dev-systemd-true; Unpinned base image: dev-firewalld-${FIREWALLD}; Unpinned base image: base; Unpinned base image: scratch; Unpinned base image: scratch; Unpinned base image: base; Unpinned base image: dev-base; Unpinned base image: dev-base; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/Dockerfile.simple ${GOLANG_IMAGE} 1 Unpinned base image: ${GOLANG_IMAGE}; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/Dockerfile.windows ${WINDOWS_BASE_IMAGE}:${WINDOWS_BASE_IMAGE_TAG} 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/busybox/Dockerfile ${WINDOWS_BASE_IMAGE}:${WINDOWS_BASE_IMAGE_TAG} 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/httpserver/Dockerfile busybox 1 Unpinned base image: busybox; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/nnp-test/Dockerfile debian:bookworm-slim 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/nano/Dockerfile.nanorc 0 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/textmate/Docker.tmbundle/Preferences/Dockerfile.tmPreferences 0 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/syntax/textmate/Docker.tmbundle/Syntaxes/Dockerfile.tmLanguage 0 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/contrib/syscall-test/Dockerfile debian:bookworm-slim 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/diagnostic/Dockerfile.client alpine 1 Unpinned base image: alpine; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/diagnostic/Dockerfile.dind docker:17.12-dind 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/networkdb-test/Dockerfile alpine 1 Unpinned base image: alpine; No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/libnetwork/cmd/ssd/Dockerfile alpine:3.7 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/github.com/docker/docker@v28.3.3+incompatible/libnetwork/support/Dockerfile docker:18-dind 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/golang.org/toolchain@v0.0.1-go1.25.7.linux-amd64/src/crypto/internal/boring/Dockerfile $ubuntu:focal 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/golang.org/toolchain@v0.0.1-go1.25.7.linux-amd64/src/crypto/internal/fips140/nistec/fiat/Dockerfile coqorg/coq:8.13.2 1 No USER directive found (defaults to root)
.gopath-loader/pkg/mod/golang.org/x/sys@v0.35.0/unix/linux/Dockerfile ubuntu:24.10 1 No USER directive found (defaults to root)
Dockerfile registry.access.redhat.com/ubi9-micro:latest 1 1001 Unpinned base image: registry.access.redhat.com/ubi9-micro:latest
Dockerfile.konflux registry.access.redhat.com/ubi9-minimal:latest 1 1001 Unpinned base image: registry.access.redhat.com/ubi9-minimal:latest