'twistlock scan on an image showscompliance issue
I am trying to do a twistlock scan on an image and I can see a compliance error stating Private keys stored in image
I have not hardcoded any keys in the image. However, I am doing a bundle install by updating the packages in Gemfile and I can see that fluentd package when installed contains .pem files in the path /usr/share/gems/gems/fluentd-1.11.5
. If I delete these .pem files the error will be resolved. But what I want to know is if it is safe to delete these .pem files or does it have any dependancy on the working of fluentd.
Sources
This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.
Source: Stack Overflow
Solution | Source |
---|