Allow Direct Path Specification for Bicep Files in MicrosoftSecurityDevOps@1 Task
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 45/100
Hướng nghiên cứu
Bắt đầu từ việc xử lý đầu vào của task MicrosoftSecurityDevOps@1 và điểm vào quét IaC/Bicep của task đó. Truy vết cách các tệp đã checkout được chọn, sau đó xác định đầu vào đường dẫn trực tiếp được yêu cầu bằng tham số bicepFile của pipeline. Hoàn tất khi task có thể quét một tệp Bicep được chỉ định mà không quét các tệp đã checkout không liên quan.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
I am using the MicrosoftSecurityDevOps@1 task in my Azure pipeline to scan Infrastructure as Code (IaC) files. My repository contains multiple Bicep modules, each located in their own subfolders. Here is a snippet of my pipeline configuration:
parameters:
- name: serviceConnection
type: string - name: resourceGroup
type: string - name: bicepFile
type: string - name: parametersFile
type: string
jobs:
- job:
displayName: "Scan IaC Templates"
pool:
vmImage: windows-latest
steps:- checkout: azure.infra.bicep
- task: MicrosoftSecurityDevOps@1
displayName: MSDO IAC
inputs:
categories: 'IaC'
The folder structure of my repository is as follows:
repo_name/
└── modules/
└── module-name/
└── module-name.bicep
Issue: Currently, there is no option to specify a direct path to a specific Bicep file within the MicrosoftSecurityDevOps@1 task. As a result, the tool attempts to scan absolutely all files being checked out, while I need to scan only the Bicep file specified in my parameters. This limitation makes it challenging to target individual Bicep files for scanning in repositories with complex structures and multiple modules.
Proposal: Introduce an option to specify a direct path to a specific Bicep file in the MicrosoftSecurityDevOps@1 task. This feature would allow for more targeted scanning of individual Bicep files.
- Ngôn ngữ chính
- TypeScript
- Star
- 86
- Fork
- 22
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/security-devops-azdevops
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
-
Checkov's SoftFail not documented, working, and ignored by MSDOCó thể làm lại được @DimaBir đã nhận 122 ngày trước và không có pull request nào đang mở. Đang mởarea:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 bình luận · 1 người được giao ·
-
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
microsoft/security-devops-azdevops#166 · 2 bình luận · 1 reaction ·
-
Spec: Promote CKV_AZUREPIPELINES_* severity from note to warningCó thể đã có người làm @DimaBir đã nhận 139 ngày trước. Đang mởarea:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 reaction · 2 người được giao ·
-
Checkov tool omits Azure Pipelines resultsCó thể làm lại được @DimaBir đã nhận 142 ngày trước và không có pull request nào đang mở. Đang mởarea:task area:tools status:team-review type:docs type:feature
microsoft/security-devops-azdevops#163 · 17 bình luận · 1 người được giao ·
Tất cả issue của microsoft/security-devops-azdevops
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
betagouv/mon-entreprise#4699 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
jaegertracing/jaeger-ui#4547 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ai-driven-qa
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
linagora/twake-calendar-frontend#1467 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
need4deed-org/sdk#267 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
auth0/universal-login#414 ·
Maintainer thường phản hồi trong vòng 1 ngày