Skip to content

Commit 256ab9d

Browse files
authored
Update security tools so it blocks build when cred detected (#25447)
1 parent b456813 commit 256ab9d

File tree

1 file changed

+16
-1
lines changed

1 file changed

+16
-1
lines changed

.azure-pipelines/security-tools.yml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,6 @@ jobs:
5353
outputFormat: sarif
5454
scanFolder: SecurityTmp
5555
suppressionsFile: tools/SecurityTools/CredScanSuppressions.json
56-
5756
- task: PowerShell@2
5857
displayName: Generate a response text file for BinSkim
5958
inputs:
@@ -88,3 +87,19 @@ jobs:
8887
inputs:
8988
artifactName: artifacts
9089
targetPath: artifacts
90+
- task: securedevelopmentteam.vss-secure-development-tools.build-task-publishsecurityanalysislogs.PublishSecurityAnalysisLogs@3
91+
# see https://eng.ms/docs/microsoft-security/microsoft-threat-protection-mtp/cloud-and-enterprise-security-cesec/security-integration/guardian-wiki/sdl-azdo-extension/publish-security-analysis-logs
92+
displayName: 'Publish Security Analysis Logs'
93+
inputs:
94+
ArtifactName: CodeAnalysisLogs
95+
ArtifactType: Container
96+
PublishProcessedResults: false
97+
AllTools: true
98+
- task: securedevelopmentteam.vss-secure-development-tools.build-task-postanalysis.PostAnalysis@2
99+
# see https://eng.ms/docs/microsoft-security/microsoft-threat-protection-mtp/cloud-and-enterprise-security-cesec/security-integration/guardian-wiki/sdl-azdo-extension/secure-development-tools-extension-for-azure-devops#post-analysis-build-break:~:text=To%20introduce%20a%20build%20break
100+
displayName: Analyze Results (may block build)
101+
inputs:
102+
GdnBreakAllTools: false
103+
GdnBreakGdnToolBinSkim: true
104+
GdnBreakGdnToolCredScan: true
105+
GdnBreakGdnToolPoliCheck: true

0 commit comments

Comments
 (0)