Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Which Defender CLI binary should be used in CI/CD pipelines — `aka.ms` or the DevOps CDN endpoint?

未关闭
#166 2 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
文档
描述清晰度
需要澄清
活跃度
冷清
技术栈
azure
领域
ci-cd, devops

调研方向

从 MicrosoftDefenderCLI@2 任务以及链接的 Defender CLI 安装、语法和 CI/CD 文档开始,然后将文档中说明的 aka.ms 二进制文件与 cli.dfd.security.azure.com 端点进行比较。完成的标准是确定 CDN 是否受支持且稳定、这些二进制文件是否属于独立产品,以及 Azure DevOps 管道应使用哪一个。

由索引模型根据 Issue 内容生成。

描述

We're integrating Defender for Cloud image scanning into our Azure DevOps pipelines. Rather than using the MicrosoftDefenderCLI@2 task (which emits ##[error] for any findings regardless of the break setting), we're invoking the CLI binary directly so we can control exit code handling and surface findings as warnings.

We've discovered there are two different CLI binaries available:

Official (aka.ms) DevOps CDN
URL https://aka.ms/defender-cli_linux-x64 https://cli.dfd.security.azure.com/public/v2/latest/Defender_linux-x64
Size ~126 MB ~24 MB
Version v2.0.3334.114 (as of May 2026) Unknown — no --version output tested
Break flag --defender-break (critical only) --fail-on <severity> (configurable threshold)
Documented Yes — Install, Syntax, CI/CD No
Auth Token-based (client ID/secret) or connector Auto-detects SYSTEM_ACCESSTOKEN
SHA-256 79F4F1EDC1DD2F99193BFFC47464023A450CFEFA03F362D7716A5E51D357B0C1 CD31528812D19142DC58DEEA0475E2610F5CC4E4D036F78EAB2FF1243CC5BB3A
Observations
  1. The CDN binary appears purpose-built for CI/CD use. It's significantly smaller (24 MB vs 126 MB), supports a configurable severity threshold (--fail-on low|medium|high|critical), and auto-detects Azure DevOps pipeline authentication via SYSTEM_ACCESSTOKEN. The URL pattern (cli.dfd.security.azure.com/public/v2/latest/) suggests it's the same binary the MicrosoftDefenderCLI@2 task downloads internally.

  2. The aka.ms CLI is the documented standalone CLI. It's referenced in the official CI/CD integration guide for non-ADO platforms (GitHub Actions, Jenkins, etc.). Its --defender-break flag only exits non-zero for "critical issues" with no configurable threshold.

  3. The --help outputs are completely different. The CDN binary exposes flags like --fail-on, --baseline, --severity, --suppress, --quiet, and --timeout that don't exist in the aka.ms binary, and vice versa (e.g. --defender-debug, --defender-output only in aka.ms).

  4. Neither binary's scan image flags match the documented CLI reference exactly. The docs list --defender-break and --defender-output as global options, which align with the aka.ms binary but not the CDN one.

Questions
  1. Is the CDN endpoint (cli.dfd.security.azure.com) a supported, stable distribution channel? Can we rely on it in production pipelines, or is it an internal implementation detail of the ADO task that could change without notice?

  2. Are these intended to be two separate products, or are they converging? The feature sets (especially --fail-on vs --defender-break) suggest they may be independently developed.

  3. For Azure DevOps pipelines where we need to bypass the task wrapper (to avoid ##[error] on non-critical findings), which binary is recommended?

主要语言
TypeScript
星标
86
派生
22
PR 合并指标
30 天内没有已合并 PR

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

microsoft/security-devops-azdevops 的其他 Issue

查看 microsoft/security-devops-azdevops 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。