Pipeline Task Does Not Fail When a Security Tool Encounters a Run Error.
@jbrotsos ci sta già lavorando.
Dal 2/3/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
When running MicrosoftSecurityDevOps@1 task in an Azure DevOps pipeline there is a misconception about the behavior of the break input .
This is seen when there is a failure in running a tool (e.g. Trivy ,Terrascan, ect. ). The expectation is that failures in security tools should cause the task to fail. However, when a tool encounters a configuration issue and fails to execute, the task logs errors but still returns a success status, continuing the pipeline execution.
##[error]Error running tool 1 of 2: trivy
##[error]Error running trivy job: 1 of 1
##[error]GuardianErrorExitCodeException: trivy completed with an Error exit code: 1. The tool did not complete successfully due to bad parameters or a scan error. Contact TrivySecSupport for assistance.
##[error]BreakException: Guardian detected one or more breaking results.
This behavior introduces a risk where security tools silently fail, potentially causing vulnerabilities to go undetected.
To avoid this one can use the break input , but the description in the documentation focuses on severity level results and does not specify task execution issues.
- task: MicrosoftSecurityDevOps@1
displayName: 'Microsoft Security DevOps'
# inputs:
# tools: string. Optional. A comma-separated list of analyzer tools to run. Values: 'bandit', 'binskim', 'checkov', 'eslint', 'templateanalyzer', 'terrascan', 'trivy'. Example 'templateanalyzer, trivy'
# break: boolean. Optional. If true, will fail this build step if any high severity level results are found. Default: false.
The MicrosoftSecurityDevOps@1 task should return error and fail if a tool that is trying to run fails to execute. Alternatively, an additional setting should be used to distinguish between: security issue (i.e., high severity findings) and task execution failure (e.g., misconfiguration or tool failure).
Please advise and do let me know if more information is needed .
- Lingua principale
- TypeScript
- Stelle
- 86
- Fork
- 22
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/security-devops-azdevops
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 68/100
-
Checkov's SoftFail not documented, working, and ignored by MSDOForse di nuovo libera @DimaBir l’ha presa 123 giorni fa e non c’è nessuna pull request aperta. Apertaarea:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 commento · 1 assegnatario ·
-
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?Aperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
microsoft/security-devops-azdevops#166 · 2 commenti · 1 reazione ·
-
Spec: Promote CKV_AZUREPIPELINES_* severity from note to warningForse già presa @DimaBir l’ha presa 139 giorni fa. Apertaarea:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 reazioni · 2 assegnatari ·
-
Checkov tool omits Azure Pipelines resultsForse di nuovo libera @DimaBir l’ha presa 142 giorni fa e non c’è nessuna pull request aperta. Apertaarea:task area:tools status:team-review type:docs type:feature
microsoft/security-devops-azdevops#163 · 17 commenti · 1 assegnatario ·
Tutte le issue di microsoft/security-devops-azdevops
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
betagouv/mon-entreprise#4699 ·
I maintainer di solito rispondono entro 3 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
jaegertracing/jaeger-ui#4547 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
ai-driven-qa
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
linagora/twake-calendar-frontend#1467 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
need4deed-org/sdk#267 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
auth0/universal-login#414 ·
I maintainer di solito rispondono entro 1 giorno