GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 30/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- azure, json, typescript, yaml
调研方向
使用提供的 Checkov 命令输出作为起点,在有配置文件和没有配置文件的情况下分别复现 MicrosoftSecurityDevOps@1 任务。检查生成的 checkov.sarif 和 msdo.sarif 文件,并比较该任务对 DownloadExternalModules 参数的处理方式。当配置的扫描产生可用的 SARIF 结果,且外部模块的行为与所提供的设置一致时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Hello All!
When i use almost vanilla MicrosoftSecurityDevOps@1 template:
parameters:
TemplatesRepoName: ''
stages:
- stage: Microsoft_Defender
displayName: Microsoft Defender for Cloud DevOps security
condition: always()
pool:
vmImage: windows-latest
jobs:
- job: Microsoft_Defender_Scan
displayName: Scan
steps:
- checkout: ${{ parameters.TemplatesRepoName }}
- checkout: self
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
config: templates/configs/checkov.gdnconfig
categories: IaC
Inside pipeline:
resources:
repositories:
- repository: templates
type: git
name: PROJ/templates
ref: refs/heads/feature/microsoft-defender-config
trigger:
- main
pr:
- main
stages:
- template: templates/microsoft-security.yml@templates
parameters:
TemplatesRepoName: templates
in the end, i got an error:
Tool run time: 11.1929338 seconds
------------------------------------------------------------------------------
Checkov completed with exit code 1
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
------------------------------------------------------------------------------
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file /home/vsts/work/1/a/.gdn/msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
```ps
Tool run time: 11.1929338 seconds
------------------------------------------------------------------------------
Checkov completed with exit code 1
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
------------------------------------------------------------------------------
Process:
Convert:
Converting any raw tool logs to Sarif format ...
Completed converting raw tool logs to Sarif format.
Import:
No tool logs to process.
Break:
Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Baselines: default
Suppression Sets: default
Policy: azuredevops
Saved file /home/vsts/work/1/a/.gdn/msdo.sarif
Found no breaking results.
Active results: 0
Skipped results: 0
Baselined results: 0
Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
##[error]Error running tool 1 of 1: checkov
##[error]Error running checkov job: 1 of 1
##[error]GuardianErrorExitCodeException: checkov completed with an Error exit code: 1. An error has occurred running the Checkov tool.
##[error]BreakException: Guardian detected one or more breaking results.
My config file is really basic:
{
"tools": [
{
"tool": {
"name": "Checkov",
"version": "Latest"
},
"arguments": {
"DownloadExternalModules": "false",
"TargetDirectory": "$(Checkov.DefaultTargetDirectory)"
}
}
]
}
Even when i set DownloadExternalModules to false, i got an error in cmd:
/home/vsts/work/_msdo/packages/nuget/Microsoft.Guardian.CheckovRedist_linux_amd64.3.2.144/tools/dist/checkov --download-external-modules false --directory ./ --output-file-path /home/vsts/work/1/s/.gdn/.r/checkov/001/checkov.sarif
##[error]2024-07-08 13:06:05,846 [MainThread ] [WARNI] Failed to download module git::https://[email protected]/ORD/PROK/_git/keyvault//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
That error is hilarious since flag is set to false but leave that...
The problem that i have is that i have a lot of errors from that pipeline:
For better reference, output with env variable set to DEBUG:
https://gist.github.com/michasacuer/c0e7127bfe537f1a15e19db5fcd8fa81
And also, sarif file is empty. This is an output from my code:
{
"$schema": "https://schemastore.azurewebsites.net/schemas/json/sarif-2.1.0-rtm.5.json",
"version": "2.1.0",
"runs": [],
"properties": {
"producer": "MicrosoftSecurityDevOps"
}
}
And scans tab in devops is empty.
When i don't use config file i got an output from msdo.safir file and scans tab has entries:
But task looks like this:
- task: MicrosoftSecurityDevOps@1
displayName: Microsoft Security DevOps
inputs:
categories: IaC
And still i got this error:
And output:
/home/vsts/work/_msdo/packages/nuget/Microsoft.Guardian.CheckovRedist_linux_amd64.3.2.144/tools/dist/checkov --directory ./ --output sarif --soft-fail --output-file-path /home/vsts/work/1/s/.gdn/.r/checkov/001/checkov.sarif
##[error]2024-07-08 13:00:23,785 [MainThread ] [WARNI] Failed to download module git::https://[email protected]/BarentzDevOps/PROJ/_git/keyvault//src?ref=v0.3:None (for external modules, the --download-external-modules flag is required)
So, to sum up:
- When i provide
configscans outputs are not saved to file - Even with variable set to
falsecheckov yells thatdownload modulesvar is required
Why it fails? What i do wrong?
- 主要语言
- TypeScript
- 星标
- 85
- 派生
- 22
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/security-devops-azdevops 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 68/100
-
Checkov's SoftFail not documented, working, and ignored by MSDO可能重新可做 @DimaBir 于 128 天前认领,目前没有进行中的 PR。 未关闭area:task area:tools status:waiting-on-author type:docs type:question
microsoft/security-devops-azdevops#169 · 1 条评论 · 已指派 1 人 ·
-
Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?未关闭
难度 5/5 一周以上 新手友好度 35/100
microsoft/security-devops-azdevops#166 · 2 条评论 · 1 个 reaction ·
-
Spec: Promote CKV_AZUREPIPELINES_* severity from note to warning可能已有人在做 @DimaBir 于 145 天前认领。 未关闭area:task area:tools status:team-review type:feature
microsoft/security-devops-azdevops#164 · 2 个 reaction · 已指派 2 人 ·
-
Checkov tool omits Azure Pipelines results可能重新可做 @DimaBir 于 148 天前认领,目前没有进行中的 PR。 未关闭area:task area:tools status:team-review type:docs type:feature
microsoft/security-devops-azdevops#163 · 17 条评论 · 已指派 1 人 ·
查看 microsoft/security-devops-azdevops 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 85/100
farbenmeer/tapi#531 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
naver/egjs-flicking#971 ·
-
难度 1/5 1 小时以内 新手友好度 85/100
维护者通常 1 天内回复
-
Tenant
难度 2/5 1-3 小时 新手友好度 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
backnotprop/plannotator#1784 ·
维护者通常 1 天内回复