Difference when run with config file and without
@DimaBir がすでに取り組んでいます。
2026年7月28日 から。
評価
この issue はまだ評価されていません。
説明
So i have a bug where i provide a config file i have a lot of errors in my pipelines.
My Example config file for checkov:
{
"tools": [
{
"tool": {
"name": "Checkov",
"version": "Latest"
},
"arguments": {
"DownloadExternalModules": "false",
"TargetDirectory": "$(Checkov.DefaultTargetDirectory)"
}
}
]
}
and everything is fine but i am getting this error, even with false setting:
D:\a\_msdo\packages\nuget\Microsoft.Guardian.CheckovRedist_windows_amd64.3.2.144\tools\dist\checkov.exe --download-external-modules false --directory .\ --output-file-path D:\a\1\s\.gdn\.r\checkov\001\checkov.sarif
##[error]2024-07-08 11:42:17,665 [ThreadPoolEx] [WARNI] Failed to download module git::https://[email protected]/ADOORG/PROJ/_git/kvmodule//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
Task still yells that DownloadExternalModules is required even when it is provided and set to false. My pipeline is the simplest template as you can imagine:
parameters:
TemplatesRepoName: ''
stages:
- stage: Microsoft_Defender
displayName: Microsoft Defender for Cloud DevOps security
condition: always()
pool:
vmImage: windows-latest
jobs:
- job: Microsoft_Defender_Scan
displayName: Scan
steps:
- checkout: ${{ parameters.TemplatesRepoName }}
- checkout: self
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
config: configs/checkov.gdnconfig
From template above i got a lot of errors:
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file D:\a\1\a\.gdn\msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
Baselined results: 0
Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
##[error]Error running tool 1 of 1: checkov
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
##[error]BreakException: Guardian detected one or more breaking results.
When i do not provide config file, no issues, only error that DownloadExternalModules is required.
Why this task behaves differently when config file for checkov is provided?
- 主要言語
- JavaScript
- スター
- 165
- フォーク
- 62
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/security-devops-action のほかの issue
-
難易度 3/5 1〜2日 初心者へのやさしさ 50/100
microsoft/security-devops-action#270 · コメント 1 件 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 38/100
microsoft/security-devops-action#104 · コメント 11 件 · リアクション 1 件 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 30/100
microsoft/security-devops-action#54 · コメント 2 件 · リアクション 2 件 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 38/100
microsoft/security-devops-action#47 · コメント 2 件 ·
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/security-devops-action の issue をすべて見る
似ている issue
-
enhancement good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
anoopcodehack/DevBoard#609 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
openai/codex-plugin-cc#813 ·
-
area: ops type: test
難易度 2/5 1〜3時間 初心者へのやさしさ 79/100
accensa/x402-facilitator-stellar#559 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
bilawalsidhu/gods-eye-view#1060 ·
メンテナーはふだん 1 日以内に返信
-
Progress difficulty filter lists Hard before Medium対応中かも @Pandamachi が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
sysprog21/codetrial#281 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信