Add cross-platform DuckDB and connector validation - #1
Conversation
|
Related legacy PR review: Microsoft PR #1170 was reviewed and closed as superseded. Its footer-version feature is already present in both current report variants, its devcontainer change became obsolete when the devcontainer was removed, and its isolated The review also exposed identical Linux/macOS CI fixture failures caused by reliance on |
|
Upstream synchronization update:
The original footer and devcontainer portions of microsoft#1170 remain superseded, so that PR stays closed and links back to this draft. |
|
Legacy container-support review completed: Microsoft PR #1169 was closed after security and lifecycle review. The original 21-file approach intercepted OAuth URLs, prepended browser wrappers to Commit |
Summary
Modernizes the local assessment foundation while preserving the existing PowerShell detection engine and report schema. This draft replaces committed platform-specific DuckDB binaries with a locked build-time dependency flow, adds native ARM64 support, hardens the localhost progress server, and adds Defender for Cloud connector inventory coverage.
This work supersedes closed Microsoft PR #1167, whose Linux architecture-selection work and review feedback informed the replacement design.
Changes
Cross-platform DuckDB
Defender for Cloud connector coverage
Microsoft.Security/securityConnectors.Localhost security
Developer and CI experience
Validation
win-arm64and returned DuckDBv1.2.1.git diff --checkpasses.Branch comparison
This PR compares
dev-feat-one-click-reviewdirectly with the fork'sdevbranch. The fork'sdevbranch remains unchanged. At creation time it was nine commits behindmicrosoft/zerotrustassessment:dev; those upstream changes do not overlap files changed here.Draft status
Draft pending validation from the new hosted Linux ARM64, Windows ARM64, and macOS jobs.