Skip to content

Move from template analyser to psrule for security audits #8

Move from template analyser to psrule for security audits

Move from template analyser to psrule for security audits #8

Triggered via pull request June 7, 2024 06:47
Status Success
Total duration 1m 2s
Artifacts

bicep-audit.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 11 warnings
build
AZR-000316: /home/runner/work/contoso-chat/contoso-chat/infra/main.test.bicep failed Azure.Deployment.SecureValue. Use secure parameters for setting properties of resources that contain sensitive information.
build
AZR-000316: main failed Azure.Deployment.SecureValue. Use secure parameters for setting properties of resources that contain sensitive information.
build
AZR-000119: kv-a12a182f2d736 failed Azure.KeyVault.Logs. Ensure audit diagnostics logs are enabled to audit Key Vault access.
build
AZR-000355: kv-a12a182f2d736 failed Azure.KeyVault.Firewall. Key Vault should only accept explicitly allowed traffic.
build
AZR-000202: sta12a182f2d736 failed Azure.Storage.Firewall. Storage Accounts should only accept explicitly allowed traffic.
build
AZR-000198: sta12a182f2d736 failed Azure.Storage.BlobPublicAccess. Storage Accounts should only accept authorized requests.
build
AZR-000280: aoai-a12a182f2d736 failed Azure.AI.PublicAccess. Restrict access of Azure AI services to authorized virtual networks.
build
AZR-000282: aoai-a12a182f2d736 failed Azure.AI.DisableLocalAuth. Authenticate requests to Azure AI services with Entra ID identities.
build
AZR-000283: aoai-a12a182f2d736 failed Azure.AI.PrivateEndpoints. Use Private Endpoints to access Azure AI services accounts.
build
AZR-000406: ai-hub-a12a182f2d736 failed Azure.ML.PublicAccess. Disable public network access from a Azure Machine Learning workspace.
build
Target object 'infra/main.test.bicep' has not been processed because no matching rules were found.
build
AZR-000388: kv-a12a182f2d736 failed Azure.KeyVault.RBAC. Key Vaults should use Azure RBAC as the authorization system for the data plane.
build
Target object 'c22da711-d619-ab3b-23c8-f7a6a7a61523' has not been processed because no matching rules were found.
build
Target object 'cb5060d8-17f9-9768-c6a8-cb6f3218c6df' has not been processed because no matching rules were found.
build
Target object '9c46f496-d7a6-b561-76eb-4bfbb946387b' has not been processed because no matching rules were found.
build
Target object '15c5c011-4dac-7894-20b1-38176bd15c41' has not been processed because no matching rules were found.
build
Target object 'eba51809-0608-6f91-2237-aa78bf7c867c' has not been processed because no matching rules were found.
build
Target object '94d7e13f-614f-554c-a7bb-49af9ec8cac6' has not been processed because no matching rules were found.
build
Target object '8bffa3b3-9785-5b96-32cb-9049fa17b186' has not been processed because no matching rules were found.
build
Target object 'de7a5e83-b1a8-58a7-6ad9-a8573de1ea47' has not been processed because no matching rules were found.
build
The process '/usr/bin/git' failed with exit code 128