web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Suggested Answer

Vulnerability scanning of AOT packages for FinOps

(4) ShareShare
ReportReport
Posted on by 15

Hi,

     I'm looking for some guidance please on vulnerability scanning of AOT packages for our new Finance & Operations (SaaS) implementation (NB: I'm relatively new to F&O build processes).

As part of our project, we will be developing customisation code that will be built on a Tier 1 environment and then deployed to other environments using LCS. 

My understanding is that the build agent will be creating an AOT package (zip file containing a variety of scripts & binaries). Our organisation has a requirement that all build artifacts are scanned for vulnerabilities before they are deployed. 

So my question is: Are there any scanning tools (X-Ray, CheckMark etc) that are able to scan these packages? 

NB: We will be using the best-practices code checker prior to build, but I don't know whether that will be sufficient for our cyber team. 

Thanks!

Tim

  • André Arnaud de Calavon Profile Picture
    307,382 Super User 2026 Season 2 on at

    Hi Tim,

    I can understand the concerns. I haven't heard of a vulnerability process before. There are some topics to be aware of.

    1) If you have a build pipeline, you can directly add the package to LCS, without user interaction.

    2) A deployable package deployment will follow a runbook process which only takes the files part of a F&O build. If the deployable package (zip file) is not according to the expectations, it will not be accepted to be installed.

  • Sukrut Parab Profile Picture
    71,741 Moderator on at

    Agree with Andre, never heard of the scanning for vulnerabilities in packages. What's the objective and what's the expected outcome after checking those?

  • tim_aemo Profile Picture
    15 on at

    Apologies for the late reply.... We have a policy that all code is vulnerability scanned to make sure no security issues are exposed by custom code.

    We use CheckMarx and X-Ray to scan other binaries that are built by our CI/CD pipelines.

  • André Arnaud de Calavon Profile Picture
    307,382 Super User 2026 Season 2 on at

    Hi Tim,

    I'm not aware of the tools you mentioned. Maybe you can test it and I would be more than happy to learn about the results.

  • Suggested answer
    AD-12051649-0 Profile Picture
    4 on at
    Hi,
    Although long time ago, I guess what you refer to here is a SAST tool for scanning the deployable packages on Azure DevOps pipelines. Maybe it's still useful for other people with similiar situation. One tool that can do is Microsoft Security DevOps. 
    You only need to bring it to your pipeline in a separate job (Job1=Scan, Job2=Build which should be dependant on Job-1). 

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the August Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
Martin Dráb Profile Picture

Martin Dráb 528 Most Valuable Professional

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 455 Super User 2026 Season 2

#3
CU10121822-0 Profile Picture

CU10121822-0 376

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans