microsoft / microsoft/security-devops-azdevops
Pipeline task 'MicrosoftSecurityDevOps@1' fails to detect the Secrets/passwords in Python files.
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 86
- Forks
- 22
- PR merge metrics
- No merged PRs in 30d
Description
Previously when using the Microsoft Security Code Analysis (MSCA) extension for Cred Scan it fails to detect the passwords in Python (*.py) files, so we planned to migrate the MicrosoftSecurityDevOps extension but it still fails to detect the password in Python files.
Also is there any option to specify the suppressions file path which was available in Microsoft Security Code Analysis (MSCA)?
Looking forward for your suggestions.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file, test, or entry point is named. Start by reproducing the MicrosoftSecurityDevOps@1 pipeline scan against a Python file containing a secret, then investigate the task's documented suppression-file options. Done means the Python secret is detected and the suppression behavior is confirmed or clearly documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, typescript
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100