Checkov tool omits Azure Pipelines results

Đang mở
#163 17 bình luận 0 reaction 1 người được giao Xem trên GitHub

@DimaBir đang làm issue này rồi.

Từ ngày 13/5/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

area:task area:tools status:team-review type:docs type:feature

When I use the Checkov tool to scan a cloned Azure DevOps Git repo with an azure-pipelines.yml, I can see CKV_AZUREPIPELINES_ results, but when I use MicrosoftSecurityDevOps@1 in a pipeline for that very same repo, scanning the whole repo, I don't get these CKV_AZUREPIPELINES_ errors.

Don't get me wrong but, this seems like a missed easy win?
Thus, I'm not sure if this is a bug with my implementation or a missing feature. As such here are some details on my implementation, please let me know if I'm missing something obvious.

Here's my .gdcnconfig, derived from https://github.com/microsoft/security-devops-azdevops/wiki#checkov-gdnconfig-sample:

{
  "tools": [
    {
      "tool": {
        "name": "checkov",
        "version": "Latest"
      },
      "arguments": {
        "Directory": "$(Checkov.DefaultTargetDirectory)",
        "Help": false,
        "Version": false,
        "OutputType": "sarif",
        "List": false,
        "Quiet": false,
        "Compact": true,
        "RunAllExternalChecks": false,
        "Soft": false,
        "ShowConfig": false,
        "CreateBaseline": false,
        "OutputBaselineAsSkipped": false,
        "NoFailOnCrash": false,
        "EnableSecretScanAllFiles": true
      },
      "outputExtension": "sarif",
      "successfulExitCodes": [
        0
      ],
      "errorExitCodes": {
        "1": "Checkov tool found issues.",
        "2": "An error has occurred running the Checkov tool."
      },
      "outputPaths": []
    }
  ]
}

And the pipeline task:

  - task: MicrosoftSecurityDevOps@1
    env:
      GDN_RUN_WORKINGDIRECTORY: $(Build.SourcesDirectory)
    inputs:
      break: true
      publish: false

I do get the other results from Checkov, although not always on par with calling standalone Checkov itself.

There seems to be some behind-the-scenes magic at work. For instance, when using MicrosoftSecurityDevOps@1 I found CKV_AZURE_177 downgraded to a warning, where it's an error when I call checkov standalone to perform what I think is the same scan.

Here's how I've been performing a manual scan with Checkov, that seems to look deeper and be more strict than the task's call does:

checkov -d "$(Build.SourcesDirectory)" --repo-root-for-plan-enrichment "$(Build.SourcesDirectory)" --deep-analysis  -o cli -o sarif --output-file-path console,$results
Ngôn ngữ chính
TypeScript
Star
86
Fork
22
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/security-devops-azdevops

Tất cả issue của microsoft/security-devops-azdevops

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.