Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secure string are written in plain text to temporary location #15

Open
pgroene opened this issue Feb 14, 2019 · 0 comments
Open

Secure string are written in plain text to temporary location #15

pgroene opened this issue Feb 14, 2019 · 0 comments

Comments

@pgroene
Copy link
Contributor

pgroene commented Feb 14, 2019

Piyush says:
February 14, 2019 at 8:35 pm Edit
Inline Powershell exposes passwords in temporary PS1 file on build server.
We have our own build servers hosted on Azure VM. The issue with inline powershell is… it copies the powershell to temporary location on build server. And even when password is stored as secret on VSTS and we also ConvertTo-SecureString. But in the copied temporary location it is stored as text in the temp/xyz.ps1 file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant