# `unsafe`

{/* Stub. Source: kix/lib/rules/security.nix, kix/lib/modules.nix (meta.unsafe). Each grant switches off the matching security rule for that package and is reported by the scorecard: raw-pvc, host-network, privileged, run-as-root. Users with a reason comment: kix/packages/velero, vaultwarden, immich, firezone, kube-prometheus-stack, node-exporter, grafana, promtail. Three application packages hold run-as-root only because their upstream image does (housekeeping/2026-09-20-three-app-packages-run-as-root-by-grant.md). */}