Auto-generated baselines by 1ES Pipeline Templates - #16380
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Pull request overview
Refreshes 1ES Pipeline Templates security baselines and pipeline tracking.
Changes:
- Adds a Guardian BinSkim baseline.
- Refreshes existing baseline signatures and dates.
- Registers pipeline 38518 scanner dates.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
guardian_baselines.gdnbaselines |
Adds generated security findings. |
.config/guardian/.gdnbaselines |
Refreshes existing BinSkim baselines. |
.config/1espt/PipelineAutobaseliningConfig.yml |
Updates pipeline baseline metadata. |
Suppressed comments (2)
guardian_baselines.gdnbaselines:30
- The expiration is 170 days after the timestamp cited by the justification, not 180 days (2026-08-20 to 2027-02-06). This mismatch is repeated throughout the generated file; align either the expiration calculation or the stated duration.
"expirationDate": "2027-02-06 12:43:38Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 12:43:38Z"
.config/guardian/.gdnbaselines:30
- The expiration is 170 days after the timestamp cited by the justification, not 180 days (2026-05-19 to 2026-11-05). This mismatch is repeated for the regenerated entries; align either the expiration calculation or the stated duration.
"expirationDate": "2026-11-05 06:07:41Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-05-19 06:07:41Z"
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "guardian-baseline": { | ||
| "name": "guardian-baseline", | ||
| "createdDate": "2026-08-20 11:42:32Z", | ||
| "lastUpdatedDate": "2026-08-20 11:44:13Z" |
| "createdDate": "2026-03-26 07:10:52Z", | ||
| "expirationDate": "2026-09-12 08:00:06Z", | ||
| "justification": "This error is baselined with an expiration date of 180 days from 2026-03-26 08:00:06Z" | ||
| "createdDate": "2026-05-19 04:56:21Z", |
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
.config/guardian/.gdnbaselines:30
- The expiration is only 170 days after the stated start date (2026-08-20 to 2027-02-06), although the justification says 180 days. This mismatch is repeated for every refreshed entry, so the actual suppression window does not match the documented policy. Please regenerate the baseline with February 16 expirations, or update the justification and policy consistently if 170 days is intentional.
"expirationDate": "2027-02-06 22:12:13Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 22:12:13Z"
guardian_baselines.gdnbaselines:30
- The expiration is only 170 days after the stated start date (2026-08-20 to 2027-02-06), although the justification says 180 days. This mismatch is repeated for every entry in this generated file, so the actual suppression window does not match the documented policy. Please regenerate the baseline with February 16 expirations, or update the justification and policy consistently if 170 days is intentional.
"expirationDate": "2027-02-06 12:43:38Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 12:43:38Z"
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
.config/guardian/.gdnbaselines:30
- The regenerated records all claim a 180-day baseline period, but 2026-08-20 plus 180 days is 2027-02-16 rather than 2027-02-06. Please regenerate all 21 records so the expiration date and justification agree; the current values make the suppression audit metadata inaccurate.
"expirationDate": "2027-02-06 22:12:13Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 22:12:13Z"
guardian_baselines.gdnbaselines:30
- The expiration metadata is internally inconsistent throughout this generated file: 180 days after 2026-08-20 is 2027-02-16, not 2027-02-06. Please regenerate all 33 records with either the intended 180-day expiration or an accurate justification; otherwise the audit trail states the wrong retention period.
"expirationDate": "2027-02-06 12:43:38Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 12:43:38Z"
|
Copilot resolve the merge conflicts in this pull request. Prefer the new code other the old. |
Co-authored-by: vmoroz <972834+vmoroz@users.noreply.github.com>
Resolved by merging |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (2)
.config/guardian/.gdnbaselines:30
- The justification says this expiration is 180 days after
2026-08-21 06:46:41Z, but2027-02-07 06:46:41Zis only 170 days later. The same mismatch appears in every refreshed entry in this baseline; please correct either the generated expiration dates or the duration in the justification.
"expirationDate": "2027-02-07 06:46:41Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-21 06:46:41Z"
guardian_baselines.gdnbaselines:30
- The justification says this expiration is 180 days after
2026-08-20 12:43:38Z, but2027-02-06 12:43:38Zis only 170 days later. This discrepancy is repeated throughout this generated file, so either the expiration dates or the stated duration need to be corrected before this becomes reliable audit metadata.
"expirationDate": "2027-02-06 12:43:38Z",
"justification": "This error is baselined with an expiration date of 180 days from 2026-08-20 12:43:38Z"
|
/azp run |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
No description provided.