You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
if ($pipePerms-and ($pipePerms.PSObject.Properties['allPipelines']) -and$pipePerms.allPipelines.authorized-eq$true) {
3900
-
$results.Add((New-ControlResult-Id "AP-05"-Status "FAIL"-Severity "High"-Control "Not Accessible to All YAML Pipelines"-Finding "$prefix — Accessible to ALL pipelines. Restrict to specific pipelines."))
3906
+
if ($pool.isHosted-eq$true) {
3907
+
$results.Add((New-ControlResult-Id "AP-05"-Status "PASS"-Severity "High"-Control "Not Accessible to All YAML Pipelines"-Finding "$prefix — Microsoft-hosted pool; broad pipeline access is the Microsoft-managed default and not a customer-side security concern."))
$results.Add((New-ControlResult-Id "AP-05"-Status "FAIL"-Severity "High"-Control "Not Accessible to All YAML Pipelines"-Finding "$prefix — Self-hosted pool accessible to ALL pipelines. Restrict to specific pipelines."))
3901
3910
} elseif ($pipePerms) {
3902
3911
$results.Add((New-ControlResult-Id "AP-05"-Status "PASS"-Severity "High"-Control "Not Accessible to All YAML Pipelines"-Finding "$prefix — Not accessible to all pipelines."))
0 commit comments