microsoft / microsoft/security-devops-azdevops
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- TypeScript
- Estrellas
- 86
- Forks
- 22
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
We're integrating Defender for Cloud image scanning into our Azure DevOps pipelines. Rather than using the MicrosoftDefenderCLI@2 task (which emits ##[error] for any findings regardless of the break setting), we're invoking the CLI binary directly so we can control exit code handling and surface findings as warnings.
We've discovered there are two different CLI binaries available:
Official (aka.ms) |
DevOps CDN | |
|---|---|---|
| URL | https://aka.ms/defender-cli_linux-x64 |
https://cli.dfd.security.azure.com/public/v2/latest/Defender_linux-x64 |
| Size | ~126 MB | ~24 MB |
| Version | v2.0.3334.114 (as of May 2026) | Unknown — no --version output tested |
| Break flag | --defender-break (critical only) |
--fail-on <severity> (configurable threshold) |
| Documented | Yes — Install, Syntax, CI/CD | No |
| Auth | Token-based (client ID/secret) or connector | Auto-detects SYSTEM_ACCESSTOKEN |
| SHA-256 | 79F4F1EDC1DD2F99193BFFC47464023A450CFEFA03F362D7716A5E51D357B0C1 |
CD31528812D19142DC58DEEA0475E2610F5CC4E4D036F78EAB2FF1243CC5BB3A |
Observations
-
The CDN binary appears purpose-built for CI/CD use. It's significantly smaller (24 MB vs 126 MB), supports a configurable severity threshold (
--fail-on low|medium|high|critical), and auto-detects Azure DevOps pipeline authentication viaSYSTEM_ACCESSTOKEN. The URL pattern (cli.dfd.security.azure.com/public/v2/latest/) suggests it's the same binary theMicrosoftDefenderCLI@2task downloads internally. -
The
aka.msCLI is the documented standalone CLI. It's referenced in the official CI/CD integration guide for non-ADO platforms (GitHub Actions, Jenkins, etc.). Its--defender-breakflag only exits non-zero for "critical issues" with no configurable threshold. -
The
--helpoutputs are completely different. The CDN binary exposes flags like--fail-on,--baseline,--severity,--suppress,--quiet, and--timeoutthat don't exist in theaka.msbinary, and vice versa (e.g.--defender-debug,--defender-outputonly inaka.ms). -
Neither binary's
scan imageflags match the documented CLI reference exactly. The docs list--defender-breakand--defender-outputas global options, which align with theaka.msbinary but not the CDN one.
Questions
-
Is the CDN endpoint (
cli.dfd.security.azure.com) a supported, stable distribution channel? Can we rely on it in production pipelines, or is it an internal implementation detail of the ADO task that could change without notice? -
Are these intended to be two separate products, or are they converging? The feature sets (especially
--fail-onvs--defender-break) suggest they may be independently developed. -
For Azure DevOps pipelines where we need to bypass the task wrapper (to avoid
##[error]on non-critical findings), which binary is recommended?
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comienza con la tarea MicrosoftDefenderCLI@2 y la documentación enlazada sobre la instalación, la sintaxis y CI/CD de Defender CLI; después, compara el binario documentado de aka.ms con el endpoint cli.dfd.security.azure.com. Se considera terminado cuando se haya establecido si la CDN es compatible y estable, si los binarios son productos independientes y cuál de ellos deberían usar las canalizaciones de Azure DevOps.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- azure
- Área
- ci-cd, devops
- Tipo de issue
- Documentación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Tranquilo
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 35/100