-
Notifications
You must be signed in to change notification settings - Fork 20
Open
Description
Azure DevOps:
azure-pipelines.yml
trigger:
- main
pool:
vmImage: ubuntu-latest
steps:
# Install Salesforce CLI
- script: npm install @salesforce/cli --global
displayName: Install Salesforce CLI
condition: eq(variables['Agent.OS'], 'Linux')
# Capture SARIF from stdout → file
- script: |
sf flow:scan --sarif > $(Build.ArtifactStagingDirectory)/results.sarif
displayName: Run Flow Scanner (stdout to SARIF)
# Upload SARIF and fail on any error/warning
- task: PublishSecurityAnalysisLogs@1
displayName: Upload SARIF (Fail on Issues)
inputs:
SarifFile: $(Build.ArtifactStagingDirectory)/results.sarif
FailOnIssues: true
Metadata
Metadata
Assignees
Labels
No labels