MED
SEC007
[SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code.
ui/ui-editors/src/app/editor/_component…:67
MED
SEC007
[SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code.
ui/ui-editors/src/app/editor/_component…:73
MED
SEC134
[SEC134] AI scaffold leftover — Lorem ipsum / example.com / John Doe in code: Lorem ipsum…
ui/ui-app/src/app/components/jsonSchema…:163
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
ui/ui-editors/src/app/editor/_component…:60
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
ui/ui-editors/src/app/editor/_component…:66
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
support-chat/src/main/resources/META-IN…:191
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
python-sdk/kiota-gen.py:55
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
common/src/main/java/io/apicurio/regist…:45
MED
SEC012
[SEC012] ZipSlip — Archive Path Traversal: Archive extraction without path validation all…
cli/src/main/java/io/apicurio/registry/…:75
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
cli/src/main/java/io/apicurio/registry/…:38
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
cli/src/main/java/io/apicurio/registry/…:22
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
cli/src/main/java/io/apicurio/registry/…:29
MED
SEC014
[SEC014] SSL Verification Disabled: SSL certificate verification is disabled, allowing ma…
.github/scripts/verify-docker-release.sh:27
MED
COMP001
[COMP001] High cognitive complexity: Function `main` has cognitive complexity 17 (SonarSo…
.github/scripts/label-classification/cl…:167
MED
DKR003
Compose service `gitops-init` image uses the latest tag
examples/gitops/docker-compose.yaml:30
MED
DKR003
Compose service `apicurio-db` image uses the latest tag
examples/event-driven-architecture/dock…:117
MED
DKR003
Compose service `ollama-init` image uses the latest tag
examples/a2a-real-world-integration/doc…:77
MED
DKR003
Compose service `ollama` image uses the latest tag
examples/a2a-real-world-integration/doc…:58
MED
DKR003
Dockerfile base image uses the latest tag
ui/in-docker/Dockerfile:1
MED
DKR003
Dockerfile base image uses the latest tag
support-chat/src/main/docker/Dockerfile…:1
MED
DKR003
Dockerfile base image uses the latest tag
support-chat/huggingface/Dockerfile:1
MED
DKR003
Dockerfile base image uses the latest tag
operator/controller/src/main/docker/Doc…:1
MED
DKR003
Dockerfile base image uses the latest tag
mcp/src/main/docker/Dockerfile.jvm:1
MED
DKR003
Dockerfile base image uses the latest tag
examples/otel-tracing/producer/Dockerfi…:4
MED
DKR003
Dockerfile base image uses the latest tag
examples/otel-tracing/consumer/Dockerfi…:4
MED
DKR003
Dockerfile base image uses the latest tag
examples/debezium-otel-tracing/order-se…:4
MED
DKR003
Dockerfile base image uses the latest tag
examples/debezium-otel-tracing/cdc-cons…:4
MED
DKR003
Dockerfile base image uses the latest tag
docs-playbook/Dockerfile:4
MED
DKR003
Dockerfile base image uses the latest tag
distro/gitops/Dockerfile:1
MED
DKR003
Dockerfile base image uses the latest tag
distro/docker/src/main/docker/Dockerfil…:1
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
DKR002
Compose service `nginx` image has no explicit tag
ui/deploy-examples/getting-started-cont…:26
MED
DKR002
Dockerfile base image has no explicit tag
ui/Dockerfile:1
MED
DKC015
Database service has no healthcheck
examples/otel-tracing/docker-compose.yml:69
MED
DKC015
Database service has no healthcheck
examples/odcs-data-contracts/docker-com…:1
MED
DKC015
Database service has no healthcheck
examples/event-driven-architecture/dock…:117
MED
DKC015
Database service has no healthcheck
examples/debezium-otel-tracing/docker-c…:84
MED
DKC015
Database service has no healthcheck
examples/debezium-otel-tracing/docker-c…:70
MED
DKR009
Dockerfile separates apt update from install
ui/in-docker/Dockerfile:4
MED
DKR009
Dockerfile separates apt update from install
docs-playbook/Dockerfile:12
MED
DKR001
Docker final stage has no non-root USER
ui/in-docker/Dockerfile:1
MED
DKR001
Docker final stage has no non-root USER
examples/tools/kafka-all/Dockerfile:4
MED
DKR001
Docker final stage has no non-root USER
docs-playbook/Dockerfile:4
MED
DKC013
Database service has no persistent data volume
examples/otel-tracing/docker-compose.yml:47
MED
DKC013
Database service has no persistent data volume
examples/otel-tracing/docker-compose.yml:33
MED
DKC013
Database service has no persistent data volume
examples/kafka-order-processing/docker-…:17
MED
DKC013
Database service has no persistent data volume
examples/kafka-order-processing/docker-…:3
MED
DKC013
Database service has no persistent data volume
examples/event-driven-architecture/dock…:76
MED
DKC013
Database service has no persistent data volume
examples/event-driven-architecture/dock…:43
MED
DKC013
Database service has no persistent data volume
examples/event-driven-architecture/dock…:6
MED
DKC013
Database service has no persistent data volume
examples/debezium-otel-tracing/docker-c…:48
MED
DKC013
Database service has no persistent data volume
examples/debezium-otel-tracing/docker-c…:34
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
examples/kafka-order-processing/docker-…:32
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
examples/debezium-otel-tracing/docker-c…:64
MED
DKC007
Compose service contains a literal secret environment value
examples/otel-tracing/docker-compose.yml:83
MED
DKC007
Compose service contains a literal secret environment value
examples/otel-tracing/docker-compose.yml:69
MED
DKC007
Compose service contains a literal secret environment value
examples/odcs-data-contracts/docker-com…:10
MED
DKC007
Compose service contains a literal secret environment value
examples/odcs-data-contracts/docker-com…:1
MED
DKC007
Compose service contains a literal secret environment value
examples/event-driven-architecture/dock…:117
MED
DKC007
Compose service contains a literal secret environment value
examples/event-driven-architecture/dock…:64
MED
DKC007
Compose service contains a literal secret environment value
examples/debezium-otel-tracing/docker-c…:158
MED
DKC007
Compose service contains a literal secret environment value
examples/debezium-otel-tracing/docker-c…:97
MED
DKC007
Compose service contains a literal secret environment value
examples/debezium-otel-tracing/docker-c…:84
MED
DKC007
Compose service contains a literal secret environment value
examples/debezium-otel-tracing/docker-c…:70
LOW
DKC015
Database service has no healthcheck
examples/otel-tracing/docker-compose.yml:47
LOW
DKC015
Database service has no healthcheck
examples/otel-tracing/docker-compose.yml:33
LOW
DKC015
Database service has no healthcheck
examples/kafka-order-processing/docker-…:17
LOW
DKC015
Database service has no healthcheck
examples/kafka-order-processing/docker-…:3
LOW
DKC015
Database service has no healthcheck
examples/event-driven-architecture/dock…:76
LOW
DKC015
Database service has no healthcheck
examples/event-driven-architecture/dock…:43
LOW
DKC015
Database service has no healthcheck
examples/event-driven-architecture/dock…:6
LOW
DKC015
Database service has no healthcheck
examples/debezium-otel-tracing/docker-c…:48
LOW
DKC015
Database service has no healthcheck
examples/debezium-otel-tracing/docker-c…:34
LOW
DKC016
App service does not wait for database health
examples/otel-tracing/docker-compose.yml:139
LOW
DKC016
App service does not wait for database health
examples/otel-tracing/docker-compose.yml:114
LOW
DKC016
App service does not wait for database health
examples/otel-tracing/docker-compose.yml:83
LOW
DKC016
App service does not wait for database health
examples/odcs-data-contracts/docker-com…:10
LOW
DKC016
App service does not wait for database health
examples/kafka-order-processing/docker-…:36
LOW
DKC016
App service does not wait for database health
examples/event-driven-architecture/dock…:93
LOW
DKC016
App service does not wait for database health
examples/event-driven-architecture/dock…:17
LOW
DKC016
App service does not wait for database health
examples/debezium-otel-tracing/docker-c…:181
LOW
DKC016
App service does not wait for database health
examples/debezium-otel-tracing/docker-c…:158
LOW
DKC016
App service does not wait for database health
examples/debezium-otel-tracing/docker-c…:125
LOW
DKC016
App service does not wait for database health
examples/debezium-otel-tracing/docker-c…:97
LOW
DKC010
Compose service lacks no-new-privileges hardening
ui/deploy-examples/getting-started/dock…:15
LOW
DKC010
Compose service lacks no-new-privileges hardening
ui/deploy-examples/getting-started/dock…:2
LOW
DKC010
Compose service lacks no-new-privileges hardening
support-chat/docker-compose.yaml:17
LOW
DKC010
Compose service lacks no-new-privileges hardening
support-chat/docker-compose.yaml:4
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/otel-tracing/docker-compose.yml:139
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/otel-tracing/docker-compose.yml:114
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/otel-tracing/docker-compose.yml:83
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/otel-tracing/docker-compose.yml:18
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/otel-tracing/docker-compose.yml:7
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/odcs-data-contracts/docker-com…:23
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/odcs-data-contracts/docker-com…:10
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/llm-artifact-types/docker-comp…:23
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/llm-artifact-types/docker-comp…:6
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/kafka-order-processing/docker-…:51
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/kafka-order-processing/docker-…:36
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/http-caching/docker-compose.ya…:68
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/http-caching/docker-compose.ya…:31
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/http-caching/docker-compose.ya…:3
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/push/docker-compose.yaml:73
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/push/docker-compose.yaml:49
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/push/docker-compose.yaml:36
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/pull-ssh/docker-compose…:71
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/pull-ssh/docker-compose…:42
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/pull-https/docker-compo…:57
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/pull-https/docker-compo…:29
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/multi-repo-pull-https/d…:64
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/multi-repo-pull-https/d…:37
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/docker-compose.yaml:79
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/gitops/docker-compose.yaml:49
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/event-driven-architecture/dock…:93
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/event-driven-architecture/dock…:64
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/event-driven-architecture/dock…:17
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:181
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:158
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:125
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:97
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:19
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/debezium-otel-tracing/docker-c…:8
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/a2a-real-world-integration/doc…:58
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/a2a-real-world-integration/doc…:44
LOW
DKC010
Compose service lacks no-new-privileges hardening
examples/a2a-real-world-integration/doc…:7
LOW
DKC010
Compose service lacks no-new-privileges hardening
docs/guides/2025/securing-apicurio-regi…:46
LOW
DKC010
Compose service lacks no-new-privileges hardening
docs/guides/2025/securing-apicurio-regi…:3
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/pg-secrets/docker…:59
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/pg-secrets/docker…:35
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/pg-no-auth/docker…:45
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/pg-no-auth/docker…:24
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/mysql-no-auth/doc…:46
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/mysql-no-auth/doc…:25
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-st…:13
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-st…:1
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:40
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:18
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:1
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:43
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:18
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:1
LOW
DKC010
Compose service lacks no-new-privileges hardening
distro/docker-compose/in-memory-with-rb…:39
LOW
DKC006
Compose service does not declare a runtime user
ui/deploy-examples/getting-started/dock…:15
LOW
DKC006
Compose service does not declare a runtime user
ui/deploy-examples/getting-started/dock…:2
LOW
DKC006
Compose service does not declare a runtime user
support-chat/docker-compose.yaml:17
LOW
DKC006
Compose service does not declare a runtime user
support-chat/docker-compose.yaml:4
LOW
DKC006
Compose service does not declare a runtime user
examples/otel-tracing/docker-compose.yml:139
LOW
DKC006
Compose service does not declare a runtime user
examples/otel-tracing/docker-compose.yml:114
LOW
DKC006
Compose service does not declare a runtime user
examples/otel-tracing/docker-compose.yml:83
LOW
DKC006
Compose service does not declare a runtime user
examples/otel-tracing/docker-compose.yml:18
LOW
DKC006
Compose service does not declare a runtime user
examples/otel-tracing/docker-compose.yml:7
LOW
DKC006
Compose service does not declare a runtime user
examples/odcs-data-contracts/docker-com…:23
LOW
DKC006
Compose service does not declare a runtime user
examples/odcs-data-contracts/docker-com…:10
LOW
DKC006
Compose service does not declare a runtime user
examples/llm-artifact-types/docker-comp…:23
LOW
DKC006
Compose service does not declare a runtime user
examples/llm-artifact-types/docker-comp…:6
LOW
DKC006
Compose service does not declare a runtime user
examples/kafka-order-processing/docker-…:51
LOW
DKC006
Compose service does not declare a runtime user
examples/kafka-order-processing/docker-…:36
LOW
DKC006
Compose service does not declare a runtime user
examples/http-caching/docker-compose.ya…:68
LOW
DKC006
Compose service does not declare a runtime user
examples/http-caching/docker-compose.ya…:31
LOW
DKC006
Compose service does not declare a runtime user
examples/http-caching/docker-compose.ya…:3
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/push/docker-compose.yaml:73
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/push/docker-compose.yaml:49
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/push/docker-compose.yaml:36
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/pull-ssh/docker-compose…:71
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/pull-ssh/docker-compose…:42
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/pull-https/docker-compo…:57
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/pull-https/docker-compo…:29
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/multi-repo-pull-https/d…:64
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/multi-repo-pull-https/d…:37
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/docker-compose.yaml:79
LOW
DKC006
Compose service does not declare a runtime user
examples/gitops/docker-compose.yaml:49
LOW
DKC006
Compose service does not declare a runtime user
examples/event-driven-architecture/dock…:93
LOW
DKC006
Compose service does not declare a runtime user
examples/event-driven-architecture/dock…:64
LOW
DKC006
Compose service does not declare a runtime user
examples/event-driven-architecture/dock…:17
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:181
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:158
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:125
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:97
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:19
LOW
DKC006
Compose service does not declare a runtime user
examples/debezium-otel-tracing/docker-c…:8
LOW
DKC006
Compose service does not declare a runtime user
examples/a2a-real-world-integration/doc…:58
LOW
DKC006
Compose service does not declare a runtime user
examples/a2a-real-world-integration/doc…:44
LOW
DKC006
Compose service does not declare a runtime user
examples/a2a-real-world-integration/doc…:7
LOW
DKC006
Compose service does not declare a runtime user
docs/guides/2025/securing-apicurio-regi…:46
LOW
DKC006
Compose service does not declare a runtime user
docs/guides/2025/securing-apicurio-regi…:3
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/pg-secrets/docker…:59
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/pg-secrets/docker…:35
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/pg-no-auth/docker…:45
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/pg-no-auth/docker…:24
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/mysql-no-auth/doc…:46
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/mysql-no-auth/doc…:25
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-st…:13
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-st…:1
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:40
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:18
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:1
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:43
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:18
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:1
LOW
DKC006
Compose service does not declare a runtime user
distro/docker-compose/in-memory-with-rb…:39