-
Notifications
You must be signed in to change notification settings - Fork 2.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added credscan steps for python #16136
Conversation
eng/pipelines/aggregate-reports.yml
Outdated
displayName: 'Post Analysis' | ||
inputs: | ||
CredScan: true | ||
- template: ../common/pipelines/templates/steps/verify-links.yml |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why did you duplicate the link checking?
eng/pipelines/aggregate-reports.yml
Outdated
displayName: 'Publish Security Analysis Logs' | ||
inputs: | ||
CredScan: true | ||
- task: securedevelopmentteam.vss-secure-development-tools.build-task-postanalysis.PostAnalysis@1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this the step that fails if there are issues or is it the Run step.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please exclude the CredScanSupression.json file.
/check-enforcer override |
…into fix_autorest_links * 'master' of https://github.com/Azure/azure-sdk-for-python: (44 commits) Added credscan steps for python (Azure#16136) [Communication] Move core dependency to setup.py from dev_requirements in communication management package (Azure#16077) Increment package version after release of azure_security_attestation (Azure#16218) T2 compute 2021 01 19 (Azure#16246) Update error message in tools repo (Azure#16245) Add LanguageDisplayName variable to LanguageSettings file (Azure#16239) Fix Eventgrid sample (Azure#16217) Adding 2020-09-01-hybrid profile (Azure#14642) Increment version for storage releases (Azure#16152) Increment package version after release of azure_storage_file_datalake (Azure#16157) make the globbing of the packages work in dev_setup from any invocation directory (Azure#16209) [Queues] Generated Queues using newest autorest version (Azure#16148) T2 confluent 2021 01 15 (Azure#16221) we are using a pool not a specific vmImage (Azure#16213) Naming Feedback - part 2 (Azure#16210) Naming feedback - part 1 (Azure#16208) Raise on bad credential (Azure#16206) Updated release date (Azure#16205) Required params must be positional (Azure#16194) Replace EventgridSharedAccessSignatureCredential with AzureSasCredential (Azure#16147) ...
Here is the aggregate-report with cred scan:
https://dev.azure.com/azure-sdk/internal/_build/results?buildId=689852&view=results