Skip to content

Change credscan to use v3 and enable scan entire repo#2740

Merged
3 commits merged intoAzure:mainfrom
sima-zhu:update_v3
Feb 11, 2022
Merged

Change credscan to use v3 and enable scan entire repo#2740
3 commits merged intoAzure:mainfrom
sima-zhu:update_v3

Conversation

@sima-zhu
Copy link
Copy Markdown
Contributor

@sima-zhu sima-zhu commented Feb 11, 2022

The PR is to fix the version issue.
Aggregate-report currently using V3 which reports less errors than v2.
We clean up the errors based v3 instead of v2.
We will use V3 for all pipelines as aggregate-report runs into OOM issue using v2.
Also, make changes to support the entire repo scanning.

@azure-sdk
Copy link
Copy Markdown
Collaborator

The following pipelines have been queued for testing:
java - template
java - template - tests
js - template
net - template
net - template - tests
python - template
python - template - tests
You can sign off on the approval gate to test the release stage of each pipeline.
See eng/common workflow

@sima-zhu sima-zhu changed the title Change credscan to use v3 and enable to scan entire repo Change credscan to use v3 and enable scan entire repo Feb 11, 2022
@azure-sdk
Copy link
Copy Markdown
Collaborator

The following pipelines have been queued for testing:
java - template
java - template - tests
js - template
net - template
net - template - tests
python - template
python - template - tests
You can sign off on the approval gate to test the release stage of each pipeline.
See eng/common workflow

@azure-sdk
Copy link
Copy Markdown
Collaborator

The following pipelines have been queued for testing:
java - template
java - template - tests
js - template
net - template
net - template - tests
python - template
python - template - tests
You can sign off on the approval gate to test the release stage of each pipeline.
See eng/common workflow

@check-enforcer-staging
Copy link
Copy Markdown

This pull request is protected by Check Enforcer.

What is Check Enforcer?

Check Enforcer helps ensure all pull requests are covered by at least one check-run (typically an Azure Pipeline). When all check-runs associated with this pull request pass then Check Enforcer itself will pass.

Why am I getting this message?

You are getting this message because Check Enforcer did not detect any check-runs being associated with this pull request within five minutes. This may indicate that your pull request is not covered by any pipelines and so Check Enforcer is correctly blocking the pull request being merged.

What should I do now?

If the check-enforcer check-run is not passing and all other check-runs associated with this PR are passing (excluding license-cla) then you could try telling Check Enforcer to evaluate your pull request again. You can do this by adding a comment to this pull request as follows:
/check-enforcer evaluate
Typically evaulation only takes a few seconds. If you know that your pull request is not covered by a pipeline and this is expected you can override Check Enforcer using the following command:
/check-enforcer override
Note that using the override command triggers alerts so that follow-up investigations can occur (PRs still need to be approved as normal).

@ghost
Copy link
Copy Markdown

ghost commented Feb 11, 2022

Hello @azure-sdk!

Because this pull request has the auto-merge label, I will be glad to assist with helping to merge this pull request once all check-in policies pass.

p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (@msftbot) and give me an instruction to get started! Learn more here.

@ghost ghost merged commit 0b83e4f into Azure:main Feb 11, 2022
@sima-zhu sima-zhu deleted the update_v3 branch February 11, 2022 06:48
This pull request was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants