build
191 TopicsVulnerabilities Introduced in CNAB after using cpa buildbundle
Hi, this is my first post here. I am following the instructions in the article https://learn.microsoft.com/en-us/partner-center/marketplace/azure-container-technical-assets-kubernetes?tabs=windows%2Clinux2 I used the command cpa buildbundle to build and upload the CNAB to my Azure Container Registry (ACR), but the Defender scan shows vulnerabilities in the CNAB bundle, even though my solution image is free of vulnerabilities. I also scanned the image with Trivy and found Critical and high vulnerabilities in Helm 3, kubectl, and the Docker Engine (Moby). The approach mentioned in the technical asset mounts the Docker engine of the host machine to the Microsoft's image mcr.microsoft.com/container-package-app:latest. My host machine has the Community Edition of Docker Engine, yet the Moby issue persists . Inside the container, I tried running `tdnf clean all && tdnf update`, which updated Moby, but I was unable to update kubectl and Helm. Should I be concerned about these vulnerabilities? I believe they may have been introduced by the CPA tool. The documentation states that for marketplace listings, the repository must be free of vulnerabilities. Additionally, it mentions in the limitations section that single containers are not supported, and my current offering contains only single image. Any tips on how I can address this issue or any remediation steps would be greatly appreciated. Thanks! AsifSolved474Views0likes6CommentsDriving innovation securely: Partnering for a safer digital future
As cybersecurity threats grow in scale and complexity, a key question continues to guide our conversations with Microsoft partners and customers: How can we protect our data and systems without slowing innovation? This is the mission behind the Secure Future Initiative (SFI)—a focused effort to help organizations turn security insight into practical action. To support this, we've introduced SFI patterns and practices, designed to equip partners and customers with actionable guidance for building more secure solutions. We’re also doubling down on our AI-first security platform, which spans identity, threat protection, data security, and compliance. The goal? Empower customers to innovate confidently with AI, knowing their environments are protected. And we recognize that our partners are essential to making that happen. With over 1 million customers already using Microsoft Security solutions, the opportunity for partners to differentiate and grow their business is greater than ever. Microsoft processes more than 84 trillion security signals daily, giving us unmatched insight into the threat landscape—and together with the expertise of our 15,000+ security partners, we’re well-positioned to secure what’s next. Read the full article here23Views1like0CommentsSecurity innovation starts here: Explore Microsoft's FY26 solution play
As cyber threats grow more sophisticated, the challenge is clear: how do we protect data and systems without slowing innovation? Microsoft's Secure Future Initiative (SFI) is our answer - and now, with newly released SFI patters and practices, partners have a blueprint to turn security strategy into real world impact. We're doubling down on our AI-first security platform - spanning identity, threat protection, data security, and compliance - so customers can innovate confidently with AI. Developers and software development companies play a pivotal role in enabling this transformation. With over a million customers already using Microsoft Security solutions and visibility into 84 trillion daily signals, the opportunity to build differentiated, high-impact solutions has never been greater. Add your expertise to our partner ecosystem of 15,000+ security specialists, and let's shape a more secure future together. With over a million customers already using Microsoft Security solutions and visibility into 84 trillion daily signals, the opportunity to build differentiated, high-impact solutions has never been greater. Add your expertise to our partner ecosystem of 15,000+ security specialists, and let’s shape a more secure future together Read the full article here21Views1like0CommentsMCAPS Start recap for software development companies
July 23 - 10 AM PST | 1 PM EST Microsoft just kicked off its new fiscal year with big updates at MCAPS Start — but what do they really mean for software development companies? In this webinar, we’ll break down the key announcements and share Carve’s expert take on what matters most for software development companies. Walk away with clear guidance on how to align your strategy with Microsoft FY26 priorities. We'll cover: What changed (and what didn’t). Where software development companies should focus time and resources. How to think about co-sell, marketplace, and solution plays. If you’re building your Microsoft partnership and want clarity for FY26 —this session is for you. Register here89Views2likes0CommentsTry a Microsoft Build demo search app with LLM functions from Azure Marketplace partner Elastic
In this guest blog post, Jonathan Simon, Sr. Product Marketing Engineer at Elastic, a longtime Microsoft and Azure Marketplace partner, presents a hybrid search solution that addresses unique challenges by using Microsoft Azure OpenAI Service, Azure Maps, and GitHub Codespaces in conjunction with Elasticsearch.240Views7likes0CommentsGet Started with Microsoft 365 AI Agents – Resources for Developers
Explore Microsoft’s latest tools and sessions designed to help you build intelligent, task-oriented agents that integrate seamlessly across Microsoft 365. 🔹 Watch: Create agents for Microsoft 365 Copilot with Microsoft 365 Agents SDK An in-depth session from Microsoft Build introducing how to create AI-powered agents that understand context, take action, and interact naturally across Microsoft 365 apps using the new Agents Toolkit. 🔹 Read: Introducing the Microsoft 365 Agents Toolkit This blog provides a high-level introduction to the Microsoft 365 Agents Toolkit, including key capabilities, architecture, and integration with Microsoft Graph and Copilot. A great starting point for developers. 🔹 Watch: Architecting your multi agent solutions with Copilot Studio and M365 Agents SDK Learn how to extend and customize Microsoft Copilot experiences using Microsoft 365 Copilot Studio—ideal for creating copilots tailored to specific business workflows with low-code tools. 🔹 Learn: Build your own agent with the M365 Agents SDK and Semantic Kernel Hands-on guidance and examples for using the Agents SDK, including setup, code structure, and tips for integrating your own logic into Microsoft Copilot experiences.105Views1like0Comments