Skip to content

Create defender-for-devops.yml

2cf55fd
Select commit
Loading
Failed to load commit list.
Merged

Create defender-for-devops.yml #12

Create defender-for-devops.yml
2cf55fd
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
GitHub Advanced Security / CodeQL succeeded Mar 18, 2025 in 4s

2 new alerts including 2 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 47 in .github/workflows/defender-for-devops.yml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions Job or Workflow does not set permissions

Check warning on line 42 in .github/workflows/defender-for-devops.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Microsoft Defender For Devops' step
Uses Step: msdo
uses 'microsoft/security-devops-action' with ref 'v1.6.0', not a pinned commit hash