Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update security-best-practices.md #14189

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

azarboon
Copy link
Contributor

@azarboon azarboon commented Dec 12, 2024

The use of IaC tools has been barely mentioned in the current documentation, whether on this page or the Secure Azure Pipelines Overview page. In fact, the use of IaC tools (not necessarily YAML), continuous scanning of these tools, and policy-as-code are crucial pillars of DevOps security. I have added this information to inform readers.

FYI, Azure Bicep is an IaC tool, but it is not YAML.

Copy link
Contributor

@azarboon : Thanks for your contribution! The author(s) have been notified to review your proposed change.

@v-dirichards
Copy link
Contributor

@chcomley

Can you review the proposed changes?

Important: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@azarboon
Copy link
Contributor Author

@jajabor4455 thanks for approving the PR. Can you please sign it off so it can be merged?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants