Closed 18swenskiq closed 1 year ago
And to confirm, I can make a successful HTTP call using the feed URL and my PAT, tested using Postman
@18swenskiq there's nothing wrong with the private NuGet feed, from what I can see in the logs. However, it appears you supplied invalid credentials for GitHub hence the failure when checking for vulnerabilities. The ruby script only checks for vulnerabilities when credentials for GitHub are provided in the task. This is then passed on to Docker via GITHUB_ACCESS_TOKEN
.
To solve this, remove any setting for github in the inputs to your task or provide the correct credentials.
Yep, you were correct. There was a rogue Github parameter I didn't see from the last person who worked on this. Thanks for the pointer, solved!
Hi @18swenskiq and @mburumaxwell , Same Issue I am also facing, Which git hub token do we need to provide? We are using azure repos.
I am currently trying to run this in my Azure DevOps pipeline using a private nuget repository, I'm getting a message that looks like this:
Now my question is, obviously it is throwing a 401 Bad Credentials issue, but it makes it this far. So what is actually throwing the "bad credentials" error? If it is Azure Devops, that is not clear at all, but it doesn't read that way in the error message to me.
(some information redacted from error)