Remove inline comment '# added' as it appears to be temporary diff annotation.
Container image should use a pinned digest or exact tag instead of 'postgres:16-alpine' for better security and reproducibility.
Remove inline comment '# added' as it appears to be temporary diff annotation.
Container image should use a pinned digest or exact tag instead of 'postgres:16-alpine' for better security and reproducibility.
Remove inline comment '# added' as it appears to be temporary diff annotation.
Remove inline comment '# added' as it appears to be temporary diff annotation.
Remove inline comment '# added' as it appears to be temporary diff annotation.
Container is missing securityContext which should be set for security best practices.
Container is missing securityContext which should be set for security best practices.
Shell script should include 'set -uo pipefail' for better error handling and safer execution.
Using ':latest' tag is discouraged as it can lead to unpredictable deployments; pin to a specific version.
Shell script should include 'set -uo pipefail' for better error handling and safer execution.