{"id":19470347,"url":"https://github.com/viglesiasce/kube-lint","last_synced_at":"2026-03-11T05:31:30.003Z","repository":{"id":66596875,"uuid":"79503247","full_name":"viglesiasce/kube-lint","owner":"viglesiasce","description":"A linter for Kubernetes resources with a customizable rule set","archived":false,"fork":false,"pushed_at":"2023-05-11T20:38:49.000Z","size":16607,"stargazers_count":156,"open_issues_count":5,"forks_count":11,"subscribers_count":11,"default_branch":"master","last_synced_at":"2025-08-14T10:43:57.390Z","etag":null,"topics":["kubernetes","linter"],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/viglesiasce.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2017-01-19T22:51:39.000Z","updated_at":"2025-04-17T09:30:14.000Z","dependencies_parsed_at":"2023-07-05T06:15:48.471Z","dependency_job_id":null,"html_url":"https://github.com/viglesiasce/kube-lint","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/viglesiasce/kube-lint","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/viglesiasce%2Fkube-lint","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/viglesiasce%2Fkube-lint/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/viglesiasce%2Fkube-lint/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/viglesiasce%2Fkube-lint/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/viglesiasce","download_url":"https://codeload.github.com/viglesiasce/kube-lint/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/viglesiasce%2Fkube-lint/sbom","scorecard":{"id":921073,"data":{"date":"2025-08-11","repo":{"name":"github.com/viglesiasce/kube-lint","commit":"f860e9ced8d2ec28e178253318d8dbf96dca02b0"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.5,"checks":[{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 2/28 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":5,"reason":"dependency not pinned by hash detected -- score normalized to 5","details":["Warn: goCommand not pinned by hash: vendor/github.com/pelletier/go-toml/test.sh:25","Warn: goCommand not pinned by hash: vendor/github.com/pelletier/go-toml/test.sh:26","Info:   2 out of   4 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.0.1-prototype not signed: https://api.github.com/repos/viglesiasce/kube-lint/releases/5213154","Warn: release artifact v0.0.1-prototype does not have provenance: https://api.github.com/repos/viglesiasce/kube-lint/releases/5213154"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 6 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":4,"reason":"6 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2021-0072 / GHSA-h62f-wm92-2cmw","Warn: Project is vulnerable to: GO-2022-0379 / GHSA-qq97-vm5h-rrhg","Warn: Project is vulnerable to: GHSA-hqxw-f8mx-cpmw","Warn: Project is vulnerable to: GO-2022-0619 / GHSA-r48q-9g5r-8q2h","Warn: Project is vulnerable to: GO-2025-3372 / GHSA-6wxm-mpqj-6jpf","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-25T03:02:17.792Z","repository_id":66596875,"created_at":"2025-08-25T03:02:17.792Z","updated_at":"2025-08-25T03:02:17.792Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30372170,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-10T21:41:54.280Z","status":"online","status_checked_at":"2026-03-11T02:00:07.027Z","response_time":84,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["kubernetes","linter"],"created_at":"2024-11-10T18:57:38.029Z","updated_at":"2026-03-11T05:31:29.976Z","avatar_url":"https://github.com/viglesiasce.png","language":"Go","funding_links":[],"categories":["Other"],"sub_categories":[],"readme":"# kube-lint\nA linter for Kubernetes resources with a customizable rule set.\n\n## Introduction\n`kube-lint` hopes to make it easy to validate that your Kubernetes configuration files and your running resources\nadhere to a standard that you define. You define a list of rules that you would like to validate against your resources\nand `kube-lint` will evaluate those rules against them.\n\nIn many organizations you will want to have a standard for what is considered \"correct\" enough to be deployed into \nyour Kubernetes clusters. You may have conventions for labels or restrictions on certain types of services being created.\nYou can use `kube-lint` during your CI/CD pipeline to gate resources being created that do not adhere to your standards.\nAdditionally you can use kube-lint to audit against a running set of resources in your cluster. \n\n***CONSIDER THIS A PROTOTYPE. PLEASE PROVIDE FEEDBACK IN THE [ISSUES](https://github.com/viglesiasce/kube-lint/issues)***\n\n***Only Pod linting is currently implemented***\n\n## Installation\n\n- Download a release from the [releases page](https://github.com/viglesiasce/kube-lint/releases/) that matches your platform.\n- Extract the archive\n\n### For MacOS\n```\nwget https://github.com/viglesiasce/kube-lint/releases/download/v0.0.1-prototype/kube-lint-prototype-darwin.tgz\ntar zxfv kube-lint-prototype-darwin.tgz\n./darwin/kube-lint -h\n```\n\n### For Linux\n```\nwget https://github.com/viglesiasce/kube-lint/releases/download/v0.0.1-prototype/kube-lint-prototype-linux.tgz\ntar zxfv kube-lint-prototype-linux.tgz\n./linux/kube-lint -h\n```\n\n## Rule configuration\nThe rule configuration file is a YAML formatted list of [KubernetesRules](https://github.com/viglesiasce/kube-lint/blob/master/pkg/rules/rules.go#L44). An example config file is \navailable at `example/config.yaml` in this repository.\n\nA KubernetesRule has the following format:\n```\nname: app-label\ndescription: Includes a label with key \"app\"\nkind: Pod\nfield: .metadata.labels.app\noperator: set\nvalueType: string\ntags:\n- operations\n- security\n```\n\n`name` is an identifier for this rule.\n\n`description` provides details about what the rule is checking for.\n\n`kind` is the type of resource this check should be done against.\n\n`field` is a [jsonpath](https://kubernetes.io/docs/user-guide/jsonpath/) used to get the value you want to evaluate against.\n\n`operator` is the check that youd like to do against your expected vs actual values (ie equal, matches, lessthan). \nFor `string` type the available operators are `equal`, `notequal`, `set`, `unset`, `matches`. For `bool` type the available\noperators are `equal`, `notequal`, `set`, `unset`. For `float64` type, the available operators are `equal`, `notequal`,\n`set`, `unset`, `greaterthan`, `lessthan`.\n\n\n`valueType` is the type of the value that needs to be evaluated. `string` is the default. `bool` and `float64` are also implemented. \n\n`tags` is a list of strings that can be used to decide whether to run this rule or not via the CLI. \n\n## Running kube-lint\n\n### Basic operation\nOnce installed you can run kube-lint from this directory as follows:\n```\nkube-lint pods --config example/config.yaml\n```\n\nTo change the rules edit `example/config.yaml`. You rulebender you.\n\n### Filtering rules by tag\nYou can evaluate a subset of rules by filtering down to only those that include certain tags. For example:\n```\nkube-lint pods --config example/config.yaml --tags security,operations\n```\n### Filtering resources by namespace\nYou can also filter which resources are evaluated by passing the `--namespace` flag as follows:\n```\nkube-lint pods --config example/config.yaml --namespace kube-system\n```\n\n## TODO if this seems like a reasonable approach to pursue\n- Replace `panic` everywhere with proper error handling\n- Add tests. Lots of tests.\n- Add docstrings to all exported functions/types/methods\n- Make -f be able to load a directories of yaml files (like kubectl)\n- Decide on how to deal with unset parameters\n- Choose a logging framework and use it\n- Add more resources (services/deployments/etc.)\n- Use ${HOME}/.kube-lint for config params\n- Develop standardized baseline of rules that are useful\n- Vendor dependencies using glide\n\n## Contributing\nAdd an issue to talk about what youd like to see changed. Lets talk about it then come up with a plan of action. \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fviglesiasce%2Fkube-lint","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fviglesiasce%2Fkube-lint","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fviglesiasce%2Fkube-lint/lists"}