@@ -77,33 +77,10 @@ stages:
7777 parameters :
7878 BaselineFilePath : $(Build.SourcesDirectory)\eng\python.gdnbaselines
7979
80- - pwsh : |
81- azcopy copy "https://azuresdkartifacts.blob.core.windows.net/policheck/PythonPoliCheckExclusion.mdb?$(azuresdk-policheck-blob-SAS)" `
82- "$(Build.BinariesDirectory)"
83- displayName: 'Download PoliCheck Exclusion Database'
84- condition: succeededOrFailed()
85-
86- - task : securedevelopmentteam.vss-secure-development-tools.build-task-policheck.PoliCheck@2
87- displayName : ' Run PoliCheck'
88- inputs :
89- targetType : F
90- targetArgument : ' $(Build.SourcesDirectory)'
91- result : PoliCheck.sarif
92- optionsFC : 0
93- optionsXS : 1
94- optionsPE : 1|2|3|4
95- optionsRulesDBPath : " $(Build.BinariesDirectory)/PythonPoliCheckExclusion.mdb"
96- optionsUEPATH : " $(Build.SourcesDirectory)/eng/guardian-tools/policheck/PolicheckExclusions.xml"
97- condition : succeededOrFailed()
98-
99- - task : securedevelopmentteam.vss-secure-development-tools.build-task-postanalysis.PostAnalysis@2
100- displayName : ' Post Analysis (PoliCheck)'
101- inputs :
102- GdnBreakAllTools : false
103- GdnBreakGdnToolPoliCheck : true
104- GdnBreakGdnToolPoliCheckSeverity : Warning
105- condition : succeededOrFailed()
106- continueOnError : true
80+ - template : /eng/common/pipelines/templates/steps/policheck.yml
81+ parameters :
82+ PublishAnalysisLogs : false
83+ ExclusionDataBaseFileName : PythonPoliCheckExclusion
10784
10885 - task : securedevelopmentteam.vss-secure-development-tools.build-task-publishsecurityanalysislogs.PublishSecurityAnalysisLogs@3
10986 displayName : ' Publish Security Analysis Logs'
0 commit comments