- stage: Fortify
jobs: -
job: SAST
timeoutInMinutes: 20
pool:
name: Fortify
steps:- checkout: self
# Fortify scan
- task: FortifySCA@7
displayName: 'SAST - FortifySCA'
inputs:
licenseFile: 'F:\fortify\fortify.license'
applicationType: 'java'
buildSourceVersion: '11'
fortifyBuildId: '${{ parameters.servicename }}-fortify'
fortifyScanType: 'LocalScan'# Export results in HTML format
- task: CmdLine@2
displayName: 'SAST Fortify Report Generation'
inputs:
script: >-
BIRTReportGenerator -template "Developer Workbook"
-source $(Build.ArtifactStagingDirectory)/sca_artifacts/${{ parameters.servicename }}-fortify.fpr
-format HTML
--UseFortifyPriorityOrder
-output $(Build.ArtifactStagingDirectory)/sca_artifacts/${{ parameters.servicename }}-fortify-report.html# Publish Fortify results as pipeline artifact
- publish: $(Build.ArtifactStagingDirectory)/sca_artifacts/${{ parameters.servicename }}-fortify-report.html
artifact: FortifyReport
Only registered users can post comments. Please, login or signup.