azure-devops-variable-group-values

Non-secret pipeline variables are readable; secret variables are masked in reads but still enter jobs as plaintext at runtime.

azurecritical service: azure:devops emits ContainsSecret

Where it sits

locationAzure DevOps variable group.variables.<name>.value
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceAzure DevOps (azure:devops)

Collection recipe

access modedata_plane
operationVariablegroups - Get
response pathvariables
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

vso.variablegroups_read

References

move · open · esc close