microsoft / microsoft/security-devops-azdevops
Really poor documentation....?
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- TypeScript
- Estrellas
- 86
- Forks
- 22
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
Almost nothing else to say, it's quite clear to anyone that hits this product and it's repo.
Let me explain why it is very disappointing its poor documentation considering that this a product cost money.
Few examples:
- where would be convenient to set the task to be executed? (first task, last one., somewhere in the middle?)
- Categories and/or tools, which one should be used and under which circunstancies?
- how to configure parameters as environment variables? the wiki page doesn't explain how to do it properly without breaking things, what the GDN_ (optional) prefix is intended for?
- how to use it?? e.g. :
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
env:
Terrascan_IacDir: '$(build.artifactstagingdirectory)/$(ENV)'
as per the documentation, this config should be correct? because it fails with the following error:
The target directory is not provided. Defaults to the working directory: /home/vsts/work/1/s.
The platform is not provided. Defaults to the current OS: Linux.
Starting tools applicability analysis...
Tools Applicability Infomation:
Found no applicable tools.Completed tools applicability analysis.
##[error]RunCommandNoOptionsException: No applicable tools were detected. Run requires at least one configuration to run. Provide at least one Guardian config or tool with --config or --tool.
##[error]MSDO CLI exited with an error exit code: 2
oh, wait! if I do this, it works!
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
env:
Terrascan_IacDir: '$(build.artifactstagingdirectory)/$(ENV)'
inputs:
command: 'run'
break: true
categories: 'IaC,secrets,code'
tools: 'terrascan'
but still not sure if I should use categories, tools or both.
Do you see my concerns?
I hope you can address the documentation gap ASAP.
Many thanks and best regards,
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comience revisando la wiki y la configuración de la tarea MicrosoftSecurityDevOps@1 que se muestra en la issue, incluidas las variables de entorno, las categorías, las herramientas y las entradas de comandos. Documente cuándo usar categorías en lugar de herramientas, cómo configurar variables como Terrascan_IacDir y proporcione un ejemplo funcional validado que cubra el fallo notificado y la configuración correcta.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- azure, typescript
- Área
- devops, documentation
- Tipo de issue
- Documentación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Estancado
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 28/100