GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 30/100
- Tipo de issue
- Error
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Stack tecnológico
- azure, json, typescript, yaml
Línea de trabajo
Reproduce la tarea MicrosoftSecurityDevOps@1 con y sin el archivo de configuración, utilizando como punto de partida la salida proporcionada del comando Checkov. Inspeccione los archivos checkov.sarif y msdo.sarif generados y compare cómo la tarea gestiona el argumento DownloadExternalModules. Se considera completado cuando el análisis configurado produce resultados SARIF utilizables y el comportamiento de los módulos externos es coherente con la configuración proporcionada.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hello All!
When i use almost vanilla MicrosoftSecurityDevOps@1 template:
parameters:
TemplatesRepoName: ''
stages:
- stage: Microsoft_Defender
displayName: Microsoft Defender for Cloud DevOps security
condition: always()
pool:
vmImage: windows-latest
jobs:
- job: Microsoft_Defender_Scan
displayName: Scan
steps:
- checkout: ${{ parameters.TemplatesRepoName }}
- checkout: self
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
config: templates/configs/checkov.gdnconfig
categories: IaC
Inside pipeline:
resources:
repositories:
- repository: templates
type: git
name: PROJ/templates
ref: refs/heads/feature/microsoft-defender-config
trigger:
- main
pr:
- main
stages:
- template: templates/microsoft-security.yml@templates
parameters:
TemplatesRepoName: templates
in the end, i got an error:
Tool run time: 11.1929338 seconds
------------------------------------------------------------------------------
Checkov completed with exit code 1
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
------------------------------------------------------------------------------
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file /home/vsts/work/1/a/.gdn/msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
```ps
Tool run time: 11.1929338 seconds
------------------------------------------------------------------------------
Checkov completed with exit code 1
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
------------------------------------------------------------------------------
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file /home/vsts/work/1/a/.gdn/msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
Baselined results: 0
Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
##[error]Error running tool 1 of 1: checkov
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
##[error]BreakException: Guardian detected one or more breaking results.
My config file is really basic:
{
"tools": [
{
"tool": {
"name": "Checkov",
"version": "Latest"
},
"arguments": {
"DownloadExternalModules": "false",
"TargetDirectory": "$(Checkov.DefaultTargetDirectory)"
}
}
]
}
Even when i set DownloadExternalModules to false, i got an error in cmd:
/home/vsts/work/_msdo/packages/nuget/Microsoft.Guardian.CheckovRedist_linux_amd64.3.2.144/tools/dist/checkov --download-external-modules false --directory ./ --output-file-path /home/vsts/work/1/s/.gdn/.r/checkov/001/checkov.sarif
##[error]2024-07-08 13:06:05,846 [MainThread ] [WARNI] Failed to download module git::https://[email protected]/ORD/PROK/_git/keyvault//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
That error is hilarious since flag is set to false but leave that...
The problem that i have is that i have a lot of errors from that pipeline:
For better reference, output with env variable set to DEBUG:
https://gist.github.com/michasacuer/c0e7127bfe537f1a15e19db5fcd8fa81
And also, sarif file is empty. This is an output from my code:
{
"$schema": "https://schemastore.azurewebsites.net/schemas/json/sarif-2.1.0-rtm.5.json",
"version": "2.1.0",
"runs": [],
"properties": {
"producer": "MicrosoftSecurityDevOps"
}
}
And scans tab in devops is empty.
When i don't use config file i got an output from msdo.safir file and scans tab has entries:
But task looks like this:
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
categories: IaC
And still i got this error:
And output:
/home/vsts/work/_msdo/packages/nuget/Microsoft.Guardian.CheckovRedist_linux_amd64.3.2.144/tools/dist/checkov --directory ./ --output sarif --soft-fail --output-file-path /home/vsts/work/1/s/.gdn/.r/checkov/001/checkov.sarif
##[error]2024-07-08 13:00:23,785 [MainThread ] [WARNI] Failed to download module git::https://[email protected]/BarentzDevOps/PROJ/_git/keyvault//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
So, to sum up:
- When i provide
configscans outputs are not saved to file - Even with variable set to
falsecheckov yells thatdownload modulesvar is required
Why it fails? What i do wrong?
- Lenguaje dominante
- TypeScript
- Estrellas
- 85
- Forks
- 22
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoft/security-devops-azdevops
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
-
Checkov's SoftFail not documented, working, and ignored by MSDOQuizá libre de nuevo @DimaBir la tomó hace 126 días y no hay ningún pull request abierto. Abiertoarea:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 comentario · 1 asignado ·
-
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?Abierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
microsoft/security-devops-azdevops#166 · 2 comentarios · 1 reacción ·
-
Spec: Promote CKV_AZUREPIPELINES_* severity from note to warningPosiblemente ocupada @DimaBir la tomó hace 142 días. Abiertoarea:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 reacciones · 2 asignados ·
-
Checkov tool omits Azure Pipelines resultsQuizá libre de nuevo @DimaBir la tomó hace 145 días y no hay ningún pull request abierto. Abiertoarea:task area:tools status:team-review type:docs type:feature
microsoft/security-devops-azdevops#163 · 17 comentarios · 1 asignado ·
Todos los issues de microsoft/security-devops-azdevops
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
bug:new
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
callstackincubator/simlock#350 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
openwatersio/maritime-zones#33 ·
Los mantenedores suelen responder en 1 día
-
Booking email verification fails for plus aliases with impersonation protection enabledPosiblemente ocupada @kankadev la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
calcom/cal.diy#30293 · 1 comentario ·
Los mantenedores suelen responder en 5 días
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
AOSSIE-Org/DebateAI#611 ·
Los mantenedores suelen responder en 3 días