-
-
Notifications
You must be signed in to change notification settings - Fork 2
Azure.DevOps.ServiceConnections.InheritedPermissions
github-actions edited this page Jan 20, 2024
·
1 revision
category: Microsoft Azure DevOps Service Connections severity: Severe online version: https://github.com/cloudyspells/PSRule.Rules.AzureDevOps/blob/main/src/PSRule.Rules.AzureDevOps/en/Azure.DevOps.ServiceConnections.InheritedPermissions.md
Service connection permissions should not be inherited from the project.
Service connection permissions should not be inherited from the project. Inherited permissions can lead to unexpected access to sensitive information and resources.
Mininum TokenType: FineGrained
Consider removing inherited permissions from the service connection and setting permissions explicitly.