Here are some additional optional configurations that can be used with Black Duck Security Scan Extension for Azure DevOps:
BRIDGECLI_INSTALL_DIRECTORY: Use this to specify the path to Bridge CLI.Note: If this is not explicitly specified, then the integration defaults to$HOME/bridge-cli. If the installed version of Bridge CLI is not the latest, then the latest version of Bridge CLI is downloaded unless you specify the version to use explicitly (as documented below).BRIDGECLI_DOWNLOAD_URL: Use this to specify the URL to Bridge CLI zip file to be downloaded and used. Examples:BRIDGECLI_DOWNLOAD_URL: https://repo.blackduck.com/bds-integrations-release/com/blackduck/integration/bridge/binaries/bridge-cli-bundle/latest/bridge-cli-bundle-win64.ziporBRIDGECLI_DOWNLOAD_URL: https://repo.blackduck.com/bds-integrations-release/com/blackduck/integration/bridge/binaries/bridge-cli-bundle/3.11.0/bridge-cli-bundle-3.11.0-win64.zip.Note: IfBRIDGECLI_DOWNLOAD_URLis not provided, Black Duck Security Scan Extension downloads the latest version of Bridge CLI from repo.blackduck.com.BRIDGECLI_DOWNLOAD_VERSION: Use this to specify the Bridge CLI version to use. If provided, the specified version of Bridge CLI is automatically downloaded from repo.blackduck.com and used. If not, the latest version is downloaded and used. Example:BRIDGECLI_DOWNLOAD_VERSION: "3.8.1".Note: If bothBRIDGECLI_DOWNLOAD_VERSIONandBRIDGECLI_DOWNLOAD_URLare provided,BRIDGECLI_DOWNLOAD_URLtakes precedence.MARK_BUILD_STATUS: Mark build status to use if policy violating issues are found. Default value:Failed. Supported values are:Failed,SucceededWithIssuesandSucceeded.Note:MARK_BUILD_STATUSis applicable only for return status 8. For any other return value, mark build status is ignored.- Black Duck SCA scan mode in Classic Editor: Auto Mode is the default and recommended scan mode. Auto Mode runs a full scan in non-PR (Pull Request) contexts, and it runs a rapid scan in PR (Pull Request) contexts. If needed, you may change the scan mode to Full Mode or Rapid Mode. In Full Mode, a full scan will be run for both PR and non-PR contexts. In Rapid Mode, a rapid scan will be run for both PR and non-PR contexts. Note: Auto Mode is recommended for PR Comment scenarios to ensure the correct scan mode is executed by bridge-cli.
- Using a proxy through Azure DevOps environment:For Classic Editor
- Go to Pipelines → Edit pipeline → Variables.
- Under Pipeline variables add:
HTTP_PROXY=http://proxy.example.com:8080HTTPS_PROXY=http://proxy.example.com:8080NO_PROXY=example.com,myserver.local:443,example.org
- Click Save.
For YAML pipelines: Define proxy variables in the YAML file:variables: - name: HTTP_PROXY value: http://proxy.example.com:8080 - name: HTTPS_PROXY value: http://proxy.example.com:8080 - name: NO_PROXY value: example.com,myserver.local:443,example.orgSupported proxy variables for Azure DevOpsTable 1. Proxy parameters Variable Description Example HTTPS_PROXY/https_proxyProxy URL for HTTPS traffic. You can include basic authentication if required. Use this when target URL is HTTPS. https://proxy.comhttps://192.168.1.1:8080https://username:password@proxy.com
HTTP_PROXY/http_proxyProxy URL for HTTP traffic. You can include basic authentication if required. Use this when target URL is HTTP. http://proxy.comhttp://192.168.1.1:8080http://username:password@proxy.com
NO_PROXY/no_proxyA comma-separated list of hosts or IP addresses that should bypass the proxy. Some clients only honor IP addresses when connections are made directly to the IP rather than a hostname. example.comexample.com,myserver.local:443,example.org
Note: Currently Coverity Local Scan is not supported with Proxy configuration.If you are using a proxy with authentication, follow these guidelines:- Proxy with auth: Users need to pass a username and password for authentication.
Example: http://user:password@proxyIP:proxyPort/
- Proxy with no auth: Users do not need to pass credentials for authentication.
Example: http://proxyIP:proxyPort/