如何在Azure DevOps Pipeline中实现Mend违规检测后构建失败且生成报告
Azure DevOps集成Mend:违规时既失败构建又保留报告
1. 调整Mend任务核心配置
将Mend任务的forceUpdate.failBuildOnPolicyViolation设为false,同时添加报告生成强制配置,确保扫描完成后生成报告:
- task: WhiteSource@21 displayName: Run Mend Scanning on L&R API inputs: projectName: "$(Build.Repository.Name)" configuration: | resolveAllDependencies=false nuget.resolveDependencies=true nuget.resolvePackagesConfigFiles=false nuget.resolveCsProjFiles=true nuget.resolveNuspecFiles=true nuget.resolveAssetsFiles=false nuget.runPreStep=true nuget.preferredEnvironment=nuget checkPolicies=true forceCheckAllDependencies=true updateInventory=true forceUpdate=true # 关闭任务直接失败,先确保报告生成 forceUpdate.failBuildOnPolicyViolation=false # 强制生成报告 report.generate=true report.format=html scanComment=Azure DevOps pipeline build scan includes=**/*.dll **/*.cs **/*.nupkg
关键说明:关闭forceUpdate.failBuildOnPolicyViolation后,Mend扫描任务会正常执行完毕并生成报告,不会中途失败导致报告丢失。
2. 添加自定义脚本检查违规并触发构建失败
Mend扫描完成后会在代理临时目录生成扫描结果JSON文件(默认路径:$(Agent.TempDirectory)/whitesource/scanResult.json),添加PowerShell/Bash任务解析该文件,检测到策略违规时主动标记构建失败。
PowerShell示例:
- task: PowerShell@2 displayName: Check Mend Policy Violations inputs: targetType: 'inline' script: | # 读取Mend扫描结果文件 $scanResultPath = "$(Agent.TempDirectory)/whitesource/scanResult.json" if (Test-Path $scanResultPath) { $scanResult = Get-Content $scanResultPath | ConvertFrom-Json # 检查是否存在策略违规 if ($scanResult.policyViolations -and $scanResult.policyViolations.count -gt 0) { Write-Host "##vso[task.logissue type=error]检测到Mend策略违规,共$($scanResult.policyViolations.count)项" Write-Host "##vso[task.complete result=Failed;]Mend策略违规" } else { Write-Host "未检测到Mend策略违规" } } else { Write-Host "##vso[task.logissue type=warning]未找到Mend扫描结果文件" }
Bash示例:
- task: Bash@3 displayName: Check Mend Policy Violations inputs: targetType: 'inline' script: | SCAN_RESULT_PATH=$(Agent.TempDirectory)/whitesource/scanResult.json if [ -f "$SCAN_RESULT_PATH" ]; then VIOLATION_COUNT=$(jq '.policyViolations | length' "$SCAN_RESULT_PATH") if [ "$VIOLATION_COUNT" -gt 0 ]; then echo "##vso[task.logissue type=error]检测到Mend策略违规,共$VIOLATION_COUNT项" echo "##vso[task.complete result=Failed;]Mend策略违规" else echo "未检测到Mend策略违规" fi else echo "##vso[task.logissue type=warning]未找到Mend扫描结果文件" fi
关键说明:使用Azure DevOps任务命令##vso[task.complete]强制标记构建失败,同时保留Mend任务生成的报告标签页。
3. 确保报告始终可访问
- 上述配置中,Mend任务已设置
report.generate=true,扫描完成后会自动在Azure DevOps构建页面生成"Mend"标签页,无论后续脚本是否触发构建失败。 - 若报告未显示,可检查Mend任务的
report.outputDirectory配置,确保报告生成在流水线工作目录下(默认会被Azure DevOps捕获)。
完整流水线片段示例
steps: # 前置构建步骤(如还原依赖) - task: NuGetCommand@2 displayName: 'Restore NuGet Packages' inputs: command: 'restore' restoreSolution: '**/*.sln' # Mend扫描任务 - task: WhiteSource@21 displayName: Run Mend Scanning on L&R API inputs: projectName: "$(Build.Repository.Name)" configuration: | resolveAllDependencies=false nuget.resolveDependencies=true nuget.resolvePackagesConfigFiles=false nuget.resolveCsProjFiles=true nuget.resolveNuspecFiles=true nuget.resolveAssetsFiles=false nuget.runPreStep=true nuget.preferredEnvironment=nuget checkPolicies=true forceCheckAllDependencies=true updateInventory=true forceUpdate=true forceUpdate.failBuildOnPolicyViolation=false report.generate=true report.format=html scanComment=Azure DevOps pipeline build scan includes=**/*.dll **/*.cs **/*.nupkg # 检查违规并触发失败 - task: PowerShell@2 displayName: Check Mend Policy Violations inputs: targetType: 'inline' script: | $scanResultPath = "$(Agent.TempDirectory)/whitesource/scanResult.json" if (Test-Path $scanResultPath) { $scanResult = Get-Content $scanResultPath | ConvertFrom-Json if ($scanResult.policyViolations -and $scanResult.policyViolations.count -gt 0) { Write-Host "##vso[task.logissue type=error]检测到Mend策略违规,共$($scanResult.policyViolations.count)项" Write-Host "##vso[task.complete result=Failed;]Mend策略违规" } } else { Write-Host "##vso[task.logissue type=warning]未找到Mend扫描结果文件" }
内容的提问来源于stack exchange,提问作者Adam
相关产品推荐
相关产品推荐

