Checkov tool omits Azure Pipelines results
@DimaBir ya está trabajando en esto.
Desde el 13/5/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
When I use the Checkov tool to scan a cloned Azure DevOps Git repo with an azure-pipelines.yml, I can see CKV_AZUREPIPELINES_ results, but when I use MicrosoftSecurityDevOps@1 in a pipeline for that very same repo, scanning the whole repo, I don't get these CKV_AZUREPIPELINES_ errors.
Don't get me wrong but, this seems like a missed easy win?
Thus, I'm not sure if this is a bug with my implementation or a missing feature. As such here are some details on my implementation, please let me know if I'm missing something obvious.
Here's my .gdcnconfig, derived from https://github.com/microsoft/security-devops-azdevops/wiki#checkov-gdnconfig-sample:
{
"tools": [
{
"tool": {
"name": "checkov",
"version": "Latest"
},
"arguments": {
"Directory": "$(Checkov.DefaultTargetDirectory)",
"Help": false,
"Version": false,
"OutputType": "sarif",
"List": false,
"Quiet": false,
"Compact": true,
"RunAllExternalChecks": false,
"Soft": false,
"ShowConfig": false,
"CreateBaseline": false,
"OutputBaselineAsSkipped": false,
"NoFailOnCrash": false,
"EnableSecretScanAllFiles": true
},
"outputExtension": "sarif",
"successfulExitCodes": [
0
],
"errorExitCodes": {
"1": "Checkov tool found issues.",
"2": "An error has occurred running the Checkov tool."
},
"outputPaths": []
}
]
}
And the pipeline task:
- task: MicrosoftSecurityDevOps@1
env:
GDN_RUN_WORKINGDIRECTORY: $(Build.SourcesDirectory)
inputs:
break: true
publish: false
I do get the other results from Checkov, although not always on par with calling standalone Checkov itself.
There seems to be some behind-the-scenes magic at work. For instance, when using MicrosoftSecurityDevOps@1 I found CKV_AZURE_177 downgraded to a warning, where it's an error when I call checkov standalone to perform what I think is the same scan.
Here's how I've been performing a manual scan with Checkov, that seems to look deeper and be more strict than the task's call does:
checkov -d "$(Build.SourcesDirectory)" --repo-root-for-plan-enrichment "$(Build.SourcesDirectory)" --deep-analysis -o cli -o sarif --output-file-path console,$results
- Lenguaje dominante
- TypeScript
- Estrellas
- 85
- Forks
- 22
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoft/security-devops-azdevops
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
-
Checkov's SoftFail not documented, working, and ignored by MSDOQuizá libre de nuevo @DimaBir la tomó hace 125 días y no hay ningún pull request abierto. Abiertoarea:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 comentario · 1 asignado ·
-
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?Abierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
microsoft/security-devops-azdevops#166 · 2 comentarios · 1 reacción ·
-
Spec: Promote CKV_AZUREPIPELINES_* severity from note to warningPosiblemente ocupada @DimaBir la tomó hace 141 días. Abiertoarea:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 reacciones · 2 asignados ·
-
enhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
microsoft/security-devops-azdevops#152 · 2 comentarios ·
Todos los issues de microsoft/security-devops-azdevops
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
prime-radiant-inc/evener#3726 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
FuRongJun-1999/dsh-memory#56 ·
Los mantenedores suelen responder en 1 día
-
bug via-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
pingdotgg/t3code#15682 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
openwatersio/slackwater.xyz#152 ·
Los mantenedores suelen responder en 1 día
-
[BUG] 请修改标题为您遇到的问题Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
OpenListTeam/OpenList-Worker#103 ·
Los mantenedores suelen responder en 1 día