diff --git a/internal/builtins/cis/M-500_default_namespace.yaml b/internal/builtins/cis/M-500_workload_in_default_namespace.yaml similarity index 100% rename from internal/builtins/cis/M-500_default_namespace.yaml rename to internal/builtins/cis/M-500_workload_in_default_namespace.yaml diff --git a/internal/builtins/cis/M-500_default_namespace_test.yaml b/internal/builtins/cis/M-500_workload_in_default_namespace_test.yaml similarity index 100% rename from internal/builtins/cis/M-500_default_namespace_test.yaml rename to internal/builtins/cis/M-500_workload_in_default_namespace_test.yaml diff --git a/internal/builtins/general/M-400_image_tag_latest.yaml b/internal/builtins/general/M-400_image_tagged_latest.yaml similarity index 100% rename from internal/builtins/general/M-400_image_tag_latest.yaml rename to internal/builtins/general/M-400_image_tagged_latest.yaml diff --git a/internal/builtins/general/M-400_image_tag_latest_test.yaml b/internal/builtins/general/M-400_image_tagged_latest_test.yaml similarity index 100% rename from internal/builtins/general/M-400_image_tag_latest_test.yaml rename to internal/builtins/general/M-400_image_tagged_latest_test.yaml diff --git a/internal/builtins/general/M-409_deprecated_image_registry.yaml b/internal/builtins/general/M-409_deprecated_image_registry.yaml index 0306a17..53d1240 100644 --- a/internal/builtins/general/M-409_deprecated_image_registry.yaml +++ b/internal/builtins/general/M-409_deprecated_image_registry.yaml @@ -13,7 +13,7 @@ # limitations under the License. id: M-409 -slug: depŕecated-image-registry +slug: deprecated-image-registry severity: Medium message: "Deprecated image registry" match: diff --git a/internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthanticated.yaml b/internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthenticated.yaml similarity index 100% rename from internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthanticated.yaml rename to internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthenticated.yaml diff --git a/internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthanticated_test.yaml b/internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthenticated_test.yaml similarity index 100% rename from internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthanticated_test.yaml rename to internal/builtins/general/M-411_role_binding_referencing_anonymous_or_unauthenticated_test.yaml diff --git a/internal/builtins/mitre/M-200_allowed_registries.yml b/internal/builtins/mitre/M-200_allowed_registries.yml index 7782f78..e4dc65b 100644 --- a/internal/builtins/mitre/M-200_allowed_registries.yml +++ b/internal/builtins/mitre/M-200_allowed_registries.yml @@ -13,7 +13,7 @@ # limitations under the License. id: M-200 -slug: image-registry +slug: allowed-registries severity: Medium message: "Image registry not allowed" match: diff --git a/internal/builtins/mitre/M-202_auto_mount_service_account.yml b/internal/builtins/mitre/M-202_auto_mount_service_account_token.yml similarity index 97% rename from internal/builtins/mitre/M-202_auto_mount_service_account.yml rename to internal/builtins/mitre/M-202_auto_mount_service_account_token.yml index a49900a..2a27ae5 100644 --- a/internal/builtins/mitre/M-202_auto_mount_service_account.yml +++ b/internal/builtins/mitre/M-202_auto_mount_service_account_token.yml @@ -13,7 +13,7 @@ # limitations under the License. id: M-202 -slug: auto-mount-sa-token +slug: auto-mount-service-account-token severity: Low message: "Automounted service account token" match: diff --git a/internal/builtins/mitre/M-202_auto_mount_service_account_test.yml b/internal/builtins/mitre/M-202_auto_mount_service_account_token_test.yml similarity index 100% rename from internal/builtins/mitre/M-202_auto_mount_service_account_test.yml rename to internal/builtins/mitre/M-202_auto_mount_service_account_token_test.yml diff --git a/internal/builtins/mitre/M-203_ssh.yml b/internal/builtins/mitre/M-203_ssh_server.yml similarity index 100% rename from internal/builtins/mitre/M-203_ssh.yml rename to internal/builtins/mitre/M-203_ssh_server.yml diff --git a/internal/builtins/mitre/M-203_ssh_test.yml b/internal/builtins/mitre/M-203_ssh_server_test.yml similarity index 100% rename from internal/builtins/mitre/M-203_ssh_test.yml rename to internal/builtins/mitre/M-203_ssh_server_test.yml diff --git a/internal/builtins/nsa/M-300_read_only_root_filesystem.yml b/internal/builtins/nsa/M-300_read_only_root_filesystem.yml index 8bed9bd..86a9a5d 100644 --- a/internal/builtins/nsa/M-300_read_only_root_filesystem.yml +++ b/internal/builtins/nsa/M-300_read_only_root_filesystem.yml @@ -13,7 +13,7 @@ # limitations under the License. id: M-300 -slug: read-only-root-fs +slug: read-only-root-filesystem severity: Low message: "Root filesystem write allowed" match: diff --git a/internal/builtins/pss/baseline/M-103_capabilities.yml b/internal/builtins/pss/baseline/M-103_capabilities_baseline.yml similarity index 98% rename from internal/builtins/pss/baseline/M-103_capabilities.yml rename to internal/builtins/pss/baseline/M-103_capabilities_baseline.yml index 2520c9e..492e71c 100644 --- a/internal/builtins/pss/baseline/M-103_capabilities.yml +++ b/internal/builtins/pss/baseline/M-103_capabilities_baseline.yml @@ -16,7 +16,7 @@ # https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_baseline.go # https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_baseline_test.go id: M-103 -slug: capabilities-added +slug: capabilities-baseline severity: High message: "Insecure capabilities" match: diff --git a/internal/builtins/pss/baseline/M-103_capabilities_test.yml b/internal/builtins/pss/baseline/M-103_capabilities_baseline_test.yml similarity index 100% rename from internal/builtins/pss/baseline/M-103_capabilities_test.yml rename to internal/builtins/pss/baseline/M-103_capabilities_baseline_test.yml diff --git a/internal/builtins/pss/baseline/M-109_seccomp.yml b/internal/builtins/pss/baseline/M-109_seccomp_baseline.yml similarity index 100% rename from internal/builtins/pss/baseline/M-109_seccomp.yml rename to internal/builtins/pss/baseline/M-109_seccomp_baseline.yml diff --git a/internal/builtins/pss/baseline/M-109_seccomp_test.yml b/internal/builtins/pss/baseline/M-109_seccomp_baseline_test.yml similarity index 100% rename from internal/builtins/pss/baseline/M-109_seccomp_test.yml rename to internal/builtins/pss/baseline/M-109_seccomp_baseline_test.yml diff --git a/internal/builtins/pss/restricted/M-115_seccomp.yml b/internal/builtins/pss/restricted/M-115_seccomp_restricted.yml similarity index 100% rename from internal/builtins/pss/restricted/M-115_seccomp.yml rename to internal/builtins/pss/restricted/M-115_seccomp_restricted.yml diff --git a/internal/builtins/pss/restricted/M-115_seccomp_test.yml b/internal/builtins/pss/restricted/M-115_seccomp_restricted_test.yml similarity index 100% rename from internal/builtins/pss/restricted/M-115_seccomp_test.yml rename to internal/builtins/pss/restricted/M-115_seccomp_restricted_test.yml diff --git a/internal/builtins/pss/restricted/M-116_capabilities.yml b/internal/builtins/pss/restricted/M-116_capabilities_restricted.yml similarity index 98% rename from internal/builtins/pss/restricted/M-116_capabilities.yml rename to internal/builtins/pss/restricted/M-116_capabilities_restricted.yml index eeb878f..622dc14 100644 --- a/internal/builtins/pss/restricted/M-116_capabilities.yml +++ b/internal/builtins/pss/restricted/M-116_capabilities_restricted.yml @@ -16,7 +16,7 @@ # https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_restricted.go # https://github.com/kubernetes/kubernetes/blob/master/staging/src/k8s.io/pod-security-admission/policy/check_capabilities_restricted_test.go id: M-116 -slug: capabilities +slug: capabilities-restricted severity: Low message: "Not allowed added/dropped capabilities" match: diff --git a/internal/builtins/pss/restricted/M-116_capabilities_test.yml b/internal/builtins/pss/restricted/M-116_capabilities_restricted_test.yml similarity index 100% rename from internal/builtins/pss/restricted/M-116_capabilities_test.yml rename to internal/builtins/pss/restricted/M-116_capabilities_restricted_test.yml