From fc1b2c579932e47f95120bc1ee86d97673c9db49 Mon Sep 17 00:00:00 2001 From: Ved Ratan <82467006+VedRatan@users.noreply.github.com> Date: Wed, 3 Jul 2024 15:14:45 +0530 Subject: [PATCH] (fix): Changed PreventExecFrpolicy from file to process (#208) * changed policy from file to process --- pkg/adapter/nimbus-kubearmor/processor/kspbuilder.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkg/adapter/nimbus-kubearmor/processor/kspbuilder.go b/pkg/adapter/nimbus-kubearmor/processor/kspbuilder.go index 0fdcb31c..36031194 100644 --- a/pkg/adapter/nimbus-kubearmor/processor/kspbuilder.go +++ b/pkg/adapter/nimbus-kubearmor/processor/kspbuilder.go @@ -268,8 +268,8 @@ func disallowChRoot() kubearmorv1.KubeArmorPolicy { func disallowBinaries() kubearmorv1.KubeArmorPolicy { // ref: https://www.tenable.com/audits/items/search?q=noexec&sort=&page=1 return kubearmorv1.KubeArmorPolicy{ Spec: kubearmorv1.KubeArmorPolicySpec{ - File: kubearmorv1.FileType{ - MatchDirectories: []kubearmorv1.FileDirectoryType{ + Process: kubearmorv1.ProcessType{ + MatchDirectories: []kubearmorv1.ProcessDirectoryType{ { Directory: "/var/tmp/", Recursive: true,