Skip to content

Commit 556d86e

Browse files
authored
Update aggregate-report to use common credscan yml and update baseline file (Azure#23090)
1 parent 66389b3 commit 556d86e

File tree

2 files changed

+907
-4979
lines changed

2 files changed

+907
-4979
lines changed

eng/pipelines/aggregate-reports.yml

Lines changed: 3 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -73,25 +73,9 @@ stages:
7373
- job: ComplianceTools
7474
timeoutInMinutes: 120
7575
steps:
76-
- task: securedevelopmentteam.vss-secure-development-tools.build-task-credscan.CredScan@3
77-
displayName: 'Run CredScan'
78-
condition: succeededOrFailed()
79-
inputs:
80-
suppressionsFile: 'eng\CredScanSuppression.json'
81-
82-
- task: securedevelopmentteam.vss-secure-development-tools.build-task-postanalysis.PostAnalysis@2
83-
displayName: 'Post Analysis'
84-
condition: succeededOrFailed()
85-
inputs:
86-
GdnBreakAllTools: false
87-
GdnBreakGdnToolCredScan: true
88-
GdnBreakGdnToolCredScanSeverity: Error
89-
GdnBreakBaselineFiles: $(Build.SourcesDirectory)\eng\python.gdnbaselines
90-
GdnBreakBaselines: baseline
91-
# Used for generating baseline file.
92-
# GdnBreakOutputBaselineFile: python
93-
# GdnBreakOutputBaseline: baseline
94-
continueOnError: true
76+
- template: /eng/common/pipelines/templates/steps/credscan.yml
77+
parameters:
78+
BaselineFilePath: $(Build.SourcesDirectory)\eng\python.gdnbaselines
9579

9680
- pwsh: |
9781
azcopy copy "https://azuresdkartifacts.blob.core.windows.net/policheck/PythonPoliCheckExclusion.mdb?$(azuresdk-policheck-blob-SAS)" `

0 commit comments

Comments
 (0)