azure-devops-pipeline-yaml-scripts

Pipeline YAML, scripts, and task inputs can hard-code credentials or print them to output.

azurecritical service: azure:devops emits ContainsSecret

Where it sits

locationAzure Repos pipeline YAML and inline script/task inputs
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceAzure DevOps (azure:devops)

Collection recipe

access modedata_plane
operationGit Items - Get
response path$value
encodingstring
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

vso.code

References

move · open · esc close