Skip to content

Update Microsoft Security DevOps action version to v1.12.0 in workflows

037ba62
Select commit
Loading
Failed to load commit list.
Merged

Add Microsoft Security DevOps workflow for IaC scanning #19

Update Microsoft Security DevOps action version to v1.12.0 in workflows
037ba62
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 21, 2025 in 3s

2 new alerts including 2 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 46 in .github/workflows/IACS-Microsoft-Security-DevOps.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'IaC Scanning - Microsoft Security DevOps (MSDO) - Defender for DevOps' step
Uses Step: msdo
uses 'microsoft/security-devops-action' with ref 'v1.12.0', not a pinned commit hash

Check warning on line 34 in .github/workflows/MSDO-Microsoft-Security-DevOps.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Microsoft Security DevOps (MSDO) - Microsoft Defender For Devops' step
Uses Step: msdo
uses 'microsoft/security-devops-action' with ref 'v1.12.0', not a pinned commit hash