azure-sql-database-code-objects

Stored procedures, functions, views, triggers, and job commands can embed connection strings or secrets. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:sql emits ContainsSecret

Where it sits

locationTDS sys.sql_modules.definition and job/agent command text
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceAzure SQL / SQL MI (azure:sql)

Collection recipe

access modedata_plane
operationTDS SELECT sys.sql_modules
response pathdefinition
encodingstring
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close