Skip to content

Conversation

@sima-zhu
Copy link
Contributor

It is currently only throwing a warning to pipeline when it detect new credential. Make changes so that it can fail the pipeline.

displayName: 'Run CredScan'
inputs:
suppressionsFile: 'eng\CredScanSuppression.json'
- task: securedevelopmentteam.vss-secure-development-tools.build-task-publishsecurityanalysislogs.PublishSecurityAnalysisLogs@3
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why would you publish before the a analysis?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am thinking to fail the post analysis if new issues coming. Then the publish step needs to either put before post analysis or run under condition of successOrFailed. Both two do not make too much difference, so I rearrange the order which is not blocking the publish step.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's fair. I agree it doesn't matter for our cases the order just seemed a little odd.

@jsquire jsquire added the no-recent-activity There has been no recent activity on this issue. label Feb 26, 2021
@jsquire
Copy link
Member

jsquire commented Feb 26, 2021

Hi @sima-zhu. There hasn't been recent engagement on this PR. Would you please be so kind as to let us know if this is still an active work stream by removing the no-recent-activity label? Otherwise, we'll close this out in 7 days.

@sima-zhu
Copy link
Contributor Author

@jsquire Thanks for reminding! Closed the PR

@sima-zhu sima-zhu closed this Feb 26, 2021
@sima-zhu sima-zhu deleted the failedOnError branch February 26, 2021 19:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-recent-activity There has been no recent activity on this issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants