Difference when run with config file and without
@DimaBir ya está trabajando en esto.
Desde el 28/7/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
So i have a bug where i provide a config file i have a lot of errors in my pipelines.
My Example config file for checkov:
{
"tools": [
{
"tool": {
"name": "Checkov",
"version": "Latest"
},
"arguments": {
"DownloadExternalModules": "false",
"TargetDirectory": "$(Checkov.DefaultTargetDirectory)"
}
}
]
}
and everything is fine but i am getting this error, even with false setting:
D:\a\_msdo\packages\nuget\Microsoft.Guardian.CheckovRedist_windows_amd64.3.2.144\tools\dist\checkov.exe --download-external-modules false --directory .\ --output-file-path D:\a\1\s\.gdn\.r\checkov\001\checkov.sarif
##[error]2024-07-08 11:42:17,665 [ThreadPoolEx] [WARNI] Failed to download module git::https://[email protected]/ADOORG/PROJ/_git/kvmodule//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
Task still yells that DownloadExternalModules is required even when it is provided and set to false. My pipeline is the simplest template as you can imagine:
parameters:
TemplatesRepoName: ''
stages:
- stage: Microsoft_Defender
displayName: Microsoft Defender for Cloud DevOps security
condition: always()
pool:
vmImage: windows-latest
jobs:
- job: Microsoft_Defender_Scan
displayName: Scan
steps:
- checkout: ${{ parameters.TemplatesRepoName }}
- checkout: self
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
config: configs/checkov.gdnconfig
From template above i got a lot of errors:
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file D:\a\1\a\.gdn\msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
Baselined results: 0
Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
##[error]Error running tool 1 of 1: checkov
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
##[error]BreakException: Guardian detected one or more breaking results.
When i do not provide config file, no issues, only error that DownloadExternalModules is required.
Why this task behaves differently when config file for checkov is provided?
- Lenguaje dominante
- JavaScript
- Estrellas
- 165
- Forks
- 62
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoft/security-devops-action
-
Dificultad 3/5 1-2 días Aptitud para principiantes 50/100
microsoft/security-devops-action#270 · 1 comentario ·
-
Help me with the example of using environment variables with values for checkov and terrascanAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
microsoft/security-devops-action#104 · 11 comentarios · 1 reacción ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
microsoft/security-devops-action#54 · 2 comentarios · 2 reacciones ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
microsoft/security-devops-action#47 · 2 comentarios ·
-
enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
Todos los issues de microsoft/security-devops-action
Issues similares
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 91/100
githubnext/gh-aw-workshop#4458 ·
Los mantenedores suelen responder en 1 día
-
Add: CartoonitoAbiertocheck:failed feeds:add
Dificultad 2/5 1-3 horas Aptitud para principiantes 63/100
iptv-org/database#37390 · 1 comentario ·
Los mantenedores suelen responder en 9 días
-
bug: directory index route root priority is overwritten when wildcard is falsePosiblemente ocupada @TalhaHunter101 la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
fastify/fastify-static#617 ·
-
agent/sec-check hive/hosted-available-lke648397-260827-5n31 security
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
Tool errors containing cycles or BigInt crash getErrorMessage and replace the original failureAbiertofactory-active factory-automatic task-bug-reproduction-success task-identify-harness-labels-done task-identify-issue-type-done
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
vercel/ai#22796 · 2 comentarios ·
Los mantenedores suelen responder en 1 día