diff --git a/assembly-module-compliance.yml b/assembly-module-compliance.yml index 4b7e020..6c13018 100644 --- a/assembly-module-compliance.yml +++ b/assembly-module-compliance.yml @@ -21,10 +21,10 @@ parameters: steps: - template: template-compliance/apiscan.yml parameters: - softwareFolder: '' - softwareName: '' - softwareVersion: '' - APIScanEnable: '' + softwareFolder: ${{ parameters.softwareFolder }} + softwareName: ${{ parameters.softwareName }} + softwareVersion: ${{ parameters.softwareVersion }} + APIScanEnable: ${{ parameters.APIScan }} - template: template-compliance/auto-applicability.yml @@ -39,14 +39,14 @@ steps: - template: template-compliance/credscan.yml parameters: - suppressionsFile: '' + suppressionsFile: ${{ parameters.suppressionsFile }} - template: template-compliance/defender.yml - template: template-compliance/TermCheck.yml parameters: - optionsRulesDBPath: '' - optionsFTPath: '' + optionsRulesDBPath: ${{ parameters.optionsRulesDBPath }} + optionsFTPath: ${{ parameters.optionsFTPath }} - template: template-compliance/vulnerability-assessment.yml diff --git a/script-module-compliance.yml b/script-module-compliance.yml index 1dfedc7..8a389a3 100644 --- a/script-module-compliance.yml +++ b/script-module-compliance.yml @@ -20,14 +20,14 @@ steps: - template: template-compliance/credscan.yml parameters: - suppressionsFile: '' + suppressionsFile: ${{ parameters.suppressionsFile }} - template: template-compliance/defender.yml - template: template-compliance/TermCheck.yml parameters: - optionsRulesDBPath: '' - optionsFTPath: '' + optionsRulesDBPath: ${{ parameters.optionsRulesDBPath }} + optionsFTPath: ${{ parameters.optionsFTPath }} - template: template-compliance/vulnerability-assessment.yml @@ -35,11 +35,12 @@ steps: - template: template-compliance/tsa-upload.yml parameters: - codeBaseName: '' + codeBaseName: ${{ parameters.codeBaseName }} - template: template-compliance/sdtreport.yml parameters: APIScan: ${{ parameters.APIScan }} - BinSkim: true + # script modules should not distribute binaries + BinSkim: false CredScan: true TermCheck: true