Checkmarx / ast-azure-plugin

The CxAST Azure DevOps plugin enables you to trigger SAST, SCA, and KICS scans directly from an Azure DevOps pipeline.
https://marketplace.visualstudio.com/items?itemName=checkmarx.checkmarx-ast-azure-plugin
Apache License 2.0
4 stars 2 forks source link

Azure | Fix IAC-Security Vulnerabilities (AST-47969) #575

Closed AlvoBen closed 1 month ago

AlvoBen commented 1 month ago

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Fix IAC-Security Vulnerabilities

References

https://checkmarx.atlassian.net/browse/AST-47969

Testing

X

Checklist

github-actions[bot] commented 1 month ago

Logo Checkmarx One – Scan Summary & Detailsac8c2d1e-f72e-4202-9cf9-b6cf71a1d1a1

Policy Management Violations

Policy Name Rule(s) Break Build
[SAST-ML0] Not allowed NEW Sast vulnerabilities true

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2024-4068 Npm-braces-3.0.2
MEDIUM Unpinned Actions Full Length Commit SHA /pr-label.yml: 10
MEDIUM Unpinned Actions Full Length Commit SHA /ast-scan.yml: 12
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 23
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 14
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 101
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 68
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 88