Skip to content

ADO Extension requiring full access PAT and not scanning for organization  #646

@Yashikaz

Description

@Yashikaz

Title

ADO Extension requiring full access PAT and not scanning for organization

Description

Using ADO Extension currently requires full access PAT which is not available sue to possible security risk, on manually giving each access on custom pat still it does not scan for organization giving 401 unauthorized error and the same for some of the controls.

Steps to reproduce

Making a starter pipeline and then adding the ADO scanner extension template, manually giving all the permissions to the PAT.

Expected behaviour

Getting the results for the project and organization similar to what we get in powershell

Actual behavior

Unauthorized 401 error for scanning the org and also some of the controls
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions