{ADO} Pin version 2.1.17 for cred scan#21230
Merged
zhoxing-ms merged 1 commit intodevfrom Feb 9, 2022
Merged
Conversation
Pin version for cred scan
2.1.17 for cred scan
Contributor
Author
|
/azp run |
|
Azure Pipelines successfully started running 2 pipeline(s). |
Collaborator
|
ADO |
wangzelin007
approved these changes
Feb 9, 2022
jiasli
reviewed
Feb 9, 2022
| inputs: | ||
| toolMajorVersion: V2 | ||
| suppressionsFile: './scripts/ci/credscan/CredScanSuppressions.json' | ||
| toolVersionV2: '2.1.17' |
Member
There was a problem hiding this comment.
evelyn-ys
approved these changes
Feb 9, 2022
3 tasks
jiasli
approved these changes
Feb 9, 2022
Member
|
Also, as an FYI: https://docs.microsoft.com/en-us/azure/security/develop/security-code-analysis-overview
Not sure what will be the replacement of CredScan. |
3 tasks
zhoxing-ms
added a commit
to zhoxing-ms/azure-cli
that referenced
this pull request
Feb 14, 2022
Pin version for cred scan
3 tasks
zhoxing-ms
added a commit
that referenced
this pull request
Feb 14, 2022
* [Packaging] BREAKING CHANGE: Drop `jmespath-terminal` from docker image (#21206) * {Packaging} Fix CI job "Test Yum Package" by using `centos7` (#21207) * Update azure-pipelines.yml for Azure Pipelines (#21230) Pin version for cred scan Co-authored-by: Jiashuo Li <4003950+jiasli@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Because package
Microsoft.Security.CredScanin taskRun Credential Scannerwas upgraded from version2.1.17to the new version2.2.7.8, a large number of issues were scanned, resulting in CI blocking pipeline linkTherefore, pin the version of
Microsoft.Security.CredScanto the last successfully version2.1.17to avoid blocking CI