Description

A Helm chart for Tekton Custom Tasks

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-tekton-custom-taskdefault81Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-tekton-custom-task

Namespace: default  |  Automount:

🔑 Permissions (8)

RoleResourceVerbsRiskTags
Role edp-tekton-custom-task-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role edp-tekton-custom-task-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole edp-tekton-custom-task-default-roleedp.epam.com/approvaltaskscreate · delete · get · list · patch · update · watchLow
ClusterRole edp-tekton-custom-task-default-roleedp.epam.com/approvaltasks/finalizersupdateLow
ClusterRole edp-tekton-custom-task-default-roleedp.epam.com/approvaltasks/statusget · patch · updateLow
ClusterRole edp-tekton-custom-task-default-roletekton.dev/customrunsget · list · patch · update · watchLow
ClusterRole edp-tekton-custom-task-default-roletekton.dev/customruns/statusget · patch · updateLow
Role edp-tekton-custom-task-leader-election-rolecore/eventscreate · patchLow

⚠️ Potential Abuse (4)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttekton-custom-tasktekton-custom-taskepamedp/tekton-custom-task:0.2.0