azure-arm-deployments-template-spec-version-content

Template Spec versions retain ARM templates and linked templates that may hard-code credentials or scripts.

azurecritical service: azure:arm-deployments emits ContainsSecret

Where it sits

locationMicrosoft.Resources/templateSpecs/versions.properties.{mainTemplate,linkedTemplates}
location kindtemplate_document
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceARM/Bicep Deployments (azure:arm-deployments)

Collection recipe

access moderead_api
operationTemplate Spec Versions - Get
response pathproperties.{mainTemplate,linkedTemplates}
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Resources/templateSpecs/versions/read

References

move · open · esc close