aquasecurity / aquasecurity/docker-bench
id: 5.5 description: "Ensure sensitive host system directories are not mounted on containers Not effective
- Dominant language
- Go
- Stars
- 222
- Forks
- 69
- PR merge metrics
- No merged PRs in 30d
Description

This is the container information when I mounted the/etc directory, but this detection passed. When I set the - flag: Source:/etc Destination in the rule
Set: false to - flag: Source:/etc
Set: false If you mount/etc again, it will be detected as not passing. I think there is a problem with the rule
Contributor guide
Research direction
Start with the implementation of rule 5.5 and compare how it handles a container mounted with /etc against the suggested Source:/etc flag configuration. Reproduce the reported mount scenario and verify that the rule flags the container as not passing when the sensitive directory is mounted.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100