azure-machinelearning-code-asset-content

Uploaded training/inference source bundles may contain hard-coded secrets or credential files.

azurecritical service: azure:machinelearning emits ContainsSecret

Where it sits

locationAzure ML code asset referenced storage content
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string private_key source_code_secret
emits edgeContainsSecret
serviceAzure ML (azure:machinelearning)

Collection recipe

access modeindirect_destination
operationRead code asset URI from workspace storage
response pathproperties.path and referenced content
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.MachineLearningServices/workspaces/codes/read

References

move · open · esc close