Enforce settable variables. If enabled, only those variables that are explicitly marked as 'Settable at queue time' can be set at queue time. You can set any variables at queue time unless this option is enabled. With this option enabled, only those variables that are explicitly marked as 'Settable at queue time' can be set. Learn more: https://learn.microsoft.com/en-us/azure/devops/pipelines/security/inputs https://learn.microsoft.com/en-us/azure/devops/organizations/security/security-best-practices
1. Navigate to Project Settings. 2. Open the Settings link under Pipelines. 3. Turn 'On' the setting 'Limit variables that can be set at queue time'.
{
"target": "ADOProjectPipelineGeneralSettings",
"if": {
"allOf": [
{
"resource": "ADOProjectPipelineGeneralSettings",
"property": "EnforceSettableVar",
"operator": "equals",
"value": true
}
]
},
"then": {
"effect": "Audit"
}
}
Copyright © DevOps Shield. All Rights Reserved. Privacy Policy | Cookie Policy | Terms and Conditions