<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability scanning for PowerBI visuals in Custom Visuals Development Discussion</title>
    <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3461135#M8046</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="397" data-lia-user-login="dm-p" class="lia-mention lia-mention-user"&gt;dm-p&lt;/a&gt;&amp;nbsp;for your quick reply, your answer was very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, as far as I understood a new 0-day vulnerability (despite the CVSS score is) in an npm package could potentially never be fixed and the &lt;EM&gt;visual&lt;/EM&gt;&amp;nbsp;will still maintain the "certified" status exposing the users to potential risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that sound correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for the help.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2023 07:09:18 GMT</pubDate>
    <dc:creator>istinbatt_all</dc:creator>
    <dc:date>2023-10-05T07:09:18Z</dc:date>
    <item>
      <title>Vulnerability scanning for PowerBI visuals</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3459063#M8043</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently discovered that it's possible to use custom visuals in PowerBI that are accessible from AppSource. In particular some of these are "PBI Certified". Microsoft states (accoring to this page: &lt;A href="https://learn.microsoft.com/en-gb/power-bi/developer/visuals/power-bi-custom-visuals-certified" target="_blank" rel="noopener"&gt;Get your Power BI visual certified&lt;/A&gt;) that, in order to get the certification for the visual, there are some requirements to be met:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;compliance with the guidelines for Power BI visuals&lt;/LI&gt;&lt;LI&gt;all required tests should pass&lt;/LI&gt;&lt;LI&gt;there should be no difference between the&amp;nbsp; submitted package and the compiled one&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;There are some other requirements about the repository, files, commands, compiling, etc. but these are not relevant for the question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At last, the question that I have and couldn't find an answer is the following:&lt;/P&gt;&lt;P&gt;if a new vulnerability is discovered (call it a zero-day if you'd like) in a package used by one of the visual or the visual itself, how is it handled? Is it entirely up to the developer to fix the code and re-submit the visual? Will Microsoft gets notified in some ways (from the developer or through automatic periodic scanning)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a look also to the FAQs (&lt;A href="https://learn.microsoft.com/en-gb/power-bi/developer/visuals/power-bi-custom-visuals-faq" target="_self"&gt;Power BI custom visuals FAQ&lt;/A&gt;) but the topic wasn't covered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance to anyone who can give me an answer on this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 08:34:01 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3459063#M8043</guid>
      <dc:creator>istinbatt_all</dc:creator>
      <dc:date>2023-10-04T08:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability scanning for PowerBI visuals</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3460638#M8045</link>
      <description>&lt;P&gt;Visuals are certified as of when they were submitted and reviewed. Nothing changes from the published visual side of things if something changes with the rules or vulnerabilities get discovered in npm packages. Provided that npm returns no warning about vulnerabilities in any required packages, this is regarded as OK. Certified visuals are not removed if certification rules change retrospectively or package vulnerabilities are discovered.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if I, as a visual author, want to submit an update to my visual, I have to address the rule changes and ensure my libraries are patched accordingly. It's routine for any author who updates their visuals regularly, as certification will fail for the update (and the last reviewed version remains in AppSource in perpetuity until the author submits a compliant update).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've never personally been contacted about package vulnerabilities in one of my published visuals, so I can assume that either (a) this doesn't happen or (b) I haven't been subjected to a significant enough incident to be contacted.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 00:33:21 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3460638#M8045</guid>
      <dc:creator>dm-p</dc:creator>
      <dc:date>2023-10-05T00:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability scanning for PowerBI visuals</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3461135#M8046</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="397" data-lia-user-login="dm-p" class="lia-mention lia-mention-user"&gt;dm-p&lt;/a&gt;&amp;nbsp;for your quick reply, your answer was very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, as far as I understood a new 0-day vulnerability (despite the CVSS score is) in an npm package could potentially never be fixed and the &lt;EM&gt;visual&lt;/EM&gt;&amp;nbsp;will still maintain the "certified" status exposing the users to potential risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that sound correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for the help.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 07:09:18 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3461135#M8046</guid>
      <dc:creator>istinbatt_all</dc:creator>
      <dc:date>2023-10-05T07:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability scanning for PowerBI visuals</title>
      <link>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3461163#M8047</link>
      <description>&lt;P&gt;Possibly. All I can say is that I haven't been requested to submit a new version of my visuals due to such an issue (and I've been submitting visuals to AppSource for ~5 years). So, as far as my experience of the process goes, a visual would remain in the store unless a new version were to be submitted, so it &lt;EM&gt;might&lt;/EM&gt; be possible that a vulnerable package could be present in an older visual that has not been updated in a long time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want something official, it would be best to contact Microsoft for their policy on how this is managed if such an event occurs. The custom visuals team doesn't actively monitor the forums, so you'd be better off contacting them at &lt;A href="mailto:pbicvsupport@microsoft.com" target="_blank"&gt;pbicvsupport@microsoft.com&lt;/A&gt;&amp;nbsp;to see if you can get confirmation about this.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 07:23:17 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Custom-Visuals-Development/Vulnerability-scanning-for-PowerBI-visuals/m-p/3461163#M8047</guid>
      <dc:creator>dm-p</dc:creator>
      <dc:date>2023-10-05T07:23:17Z</dc:date>
    </item>
  </channel>
</rss>

