web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Suggested Answer

Vulnerability scanning of AOT packages for FinOps

(3) ShareShare
ReportReport
Posted on by 13

Hi,

     I'm looking for some guidance please on vulnerability scanning of AOT packages for our new Finance & Operations (SaaS) implementation (NB: I'm relatively new to F&O build processes).

As part of our project, we will be developing customisation code that will be built on a Tier 1 environment and then deployed to other environments using LCS. 

My understanding is that the build agent will be creating an AOT package (zip file containing a variety of scripts & binaries). Our organisation has a requirement that all build artifacts are scanned for vulnerabilities before they are deployed. 

So my question is: Are there any scanning tools (X-Ray, CheckMark etc) that are able to scan these packages? 

NB: We will be using the best-practices code checker prior to build, but I don't know whether that will be sufficient for our cyber team. 

Thanks!

Tim

I have the same question (0)
  • André Arnaud de Calavon Profile Picture
    300,721 Super User 2025 Season 2 on at
    RE: Vulnerability scanning of AOT packages for FinOps

    Hi Tim,

    I can understand the concerns. I haven't heard of a vulnerability process before. There are some topics to be aware of.

    1) If you have a build pipeline, you can directly add the package to LCS, without user interaction.

    2) A deployable package deployment will follow a runbook process which only takes the files part of a F&O build. If the deployable package (zip file) is not according to the expectations, it will not be accepted to be installed.

  • Sukrut Parab Profile Picture
    71,710 Moderator on at
    RE: Vulnerability scanning of AOT packages for FinOps

    Agree with Andre, never heard of the scanning for vulnerabilities in packages. What's the objective and what's the expected outcome after checking those?

  • tim_aemo Profile Picture
    13 on at
    RE: Vulnerability scanning of AOT packages for FinOps

    Apologies for the late reply.... We have a policy that all code is vulnerability scanned to make sure no security issues are exposed by custom code.

    We use CheckMarx and X-Ray to scan other binaries that are built by our CI/CD pipelines.

  • André Arnaud de Calavon Profile Picture
    300,721 Super User 2025 Season 2 on at
    RE: Vulnerability scanning of AOT packages for FinOps

    Hi Tim,

    I'm not aware of the tools you mentioned. Maybe you can test it and I would be more than happy to learn about the results.

  • Suggested answer
    AD-12051649-0 Profile Picture
    4 on at
    Vulnerability scanning of AOT packages for FinOps
    Hi,
    Although long time ago, I guess what you refer to here is a SAST tool for scanning the deployable packages on Azure DevOps pipelines. Maybe it's still useful for other people with similiar situation. One tool that can do is Microsoft Security DevOps. 
    You only need to bring it to your pipeline in a separate job (Job1=Scan, Job2=Build which should be dependant on Job-1). 

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
Martin Dráb Profile Picture

Martin Dráb 683 Most Valuable Professional

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 563 Super User 2025 Season 2

#3
Sohaib Cheema Profile Picture

Sohaib Cheema 398 User Group Leader

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans