microsoft / microsoft/security-devops-azdevops
Microsoft security DevOps task is breaking when we use 3rd party modules/private repositories.
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- TypeScript
- Sterne
- 86
- Forks
- 22
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
Configured microsoft security DevOps task but it is breaking when we use 3rd party modules/private repositories.
Below is the Yaml i was using.
- task: MicrosoftSecurityDevOps@1
displayName: 'Microsoft Security DevOps'
inputs:
categories: 'IaC'
publish: true
artifactName: CodeAnalysisLogs
Tried with a private repository and it is breaking with the below error. Is there a way to skip for 3rd party modules?
module "lz_vending" {
source = "Azure/lz-vending/azurerm"
version = "3.1.0"
}
Error
Error running terrascan job: 1 of 1Microsoft Security DevOps | |
-- | -- | --
| GuardianErrorExitCodeException: terrascan completed with an Error exit code: 2. Unexpected exit code. Please check https://docs.accurics.com/projects/accurics-terrascan/en/latest/ for more information.Microsoft Security DevOps | |
| Error running tool 1 of 2: terrascanMicrosoft Security DevOps | |
| Error running terrascan job: 1 of 1Microsoft Security DevOps | |
| GuardianErrorExitCodeException: terrascan completed with an Error exit code: 2. Unexpected exit code. Please check https://docs.accurics.com/projects/accurics-terrascan/en/latest/ for more information.Microsoft Security DevOps | |
| BreakException: Guardian detected one or more breaking results.
Is there a way to fix or skip this?
Any help is appreciated.
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, die Azure DevOps-Pipeline mithilfe des gezeigten MicrosoftSecurityDevOps@1 YAML und eines privaten Terraform-Moduls wie Azure/lz-vending/azurerm zu reproduzieren. Untersuche, wie der IaC Terrascan-Job mit Modulen von Drittanbietern oder privaten Modulen umgeht, und definiere, ob das erwartete Ergebnis ein erfolgreiches Scannen oder ein explizites Überspringen ohne einen fehlerauslösenden Fehler ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- azure, terraform, typescript
- Bereich
- devops, infrastructure, security
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 30/100