This document serves as the public-facing evidence of the project's engineering quality and security baseline. Below is the static-analysis and misconfiguration audit report for the v1.0 release candidate manifests.
All tools are configured to run automatically in CI on every Pull Request to prevent regressions.
Tool: kube-linter (StackRox)
Target: config/, helm/, install.yaml
Status: PASS (with documented suppressions)
Findings Triage:
unset-cpu-requirements: Resolved. Requests and limits default to a measured envelope (re-baselined 2026-08-22: steady 1–2m CPU / ~61Mi at 1,001 workloads on live GKE, v1.2.0 and v1.3.0, dual-sampled via metrics-server and kubelet counter deltas; see README “Performance footprint”). The 1-CPU limit is ~3x the ~370m convergence-burst maximum observed in the v1.1.0-era Kind qualification — retained as the burst upper bound — bounding runaway consumption without throttling BOM-generation bursts.run-as-non-root: Suppressed. The container currently runs as non-root (uid 65532), but the explicitrunAsNonRoot: truesecurityContext flag is missing from the default kubebuilder scaffolding. Will be fixed in v1.1.read-only-root-fs: Suppressed. Requires mounting an emptyDir for/tmp. Will be fixed in v1.1.
Tool: kubeconform
Target: Kubernetes versions 1.27.0 through 1.31.0
Status: PASS
Output Snippet:
Summary: 14 resources found in install.yaml - Valid: 14, Invalid: 0, Errors: 0, Skipped: 0
Summary: 14 resources found in helm-template.yaml - Valid: 14, Invalid: 0, Errors: 0, Skipped: 0
All emitted manifests strictly conform to the Kubernetes OpenAPI schemas for the supported version range.
Tool: kubeaudit (Shopify)
Target: install.yaml, helm-template.yaml
Status: PASS (Soft-fail warnings only)
Findings Triage:
CapabilityAdded: No privileged capabilities are added.ReadOnlyRootFilesystemFalse: Flagged as a warning. Addressed via suppression.SeccompProfileMissing: Flagged as a warning on older Kubernetes versions.
Tool: conftest (with kubernetes-best-practices policies)
Target: install.yaml, helm-template.yaml
Status: PASS
Output Snippet:
14 tests, 14 passed, 0 warnings, 0 failures, 0 exceptions
Tool: trivy config (Aqua Security)
Target: Repository manifests
Status: PASS (No HIGH/CRITICAL findings)
Findings Triage:
Trivy flags KSV012 (Read-only file system) and KSV014 (Root file system) as MEDIUM severity. These do not cross our HIGH/CRITICAL hard-fail threshold and are tracked for remediation in a future PR.
Tool: helm
Target: charts/k8s-aibom
Status: PASS
Output Snippet:
==> Linting charts/k8s-aibom
[INFO] Chart.yaml: icon is recommended
1 chart(s) linted, 0 chart(s) failed
Note: Any issues surfaced in this report that require source-code fixes are intentionally preserved in the v1.0 codebase and tracked separately to maintain a stable release baseline.