You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure DevOps Pipeline中实现Mend违规检测后构建失败且生成报告

Azure DevOps集成Mend:违规时既失败构建又保留报告

1. 调整Mend任务核心配置

将Mend任务的forceUpdate.failBuildOnPolicyViolation设为false,同时添加报告生成强制配置,确保扫描完成后生成报告:

- task: WhiteSource@21
  displayName: Run Mend Scanning on L&R API
  inputs:
    projectName: "$(Build.Repository.Name)"
    configuration: |
      resolveAllDependencies=false
      nuget.resolveDependencies=true
      nuget.resolvePackagesConfigFiles=false
      nuget.resolveCsProjFiles=true
      nuget.resolveNuspecFiles=true
      nuget.resolveAssetsFiles=false
      nuget.runPreStep=true
      nuget.preferredEnvironment=nuget
      checkPolicies=true
      forceCheckAllDependencies=true
      updateInventory=true
      forceUpdate=true
      # 关闭任务直接失败,先确保报告生成
      forceUpdate.failBuildOnPolicyViolation=false
      # 强制生成报告
      report.generate=true
      report.format=html
      scanComment=Azure DevOps pipeline build scan
      includes=**/*.dll **/*.cs **/*.nupkg

关键说明:关闭forceUpdate.failBuildOnPolicyViolation后,Mend扫描任务会正常执行完毕并生成报告,不会中途失败导致报告丢失。

2. 添加自定义脚本检查违规并触发构建失败

Mend扫描完成后会在代理临时目录生成扫描结果JSON文件(默认路径:$(Agent.TempDirectory)/whitesource/scanResult.json),添加PowerShell/Bash任务解析该文件,检测到策略违规时主动标记构建失败。

PowerShell示例:

- task: PowerShell@2
  displayName: Check Mend Policy Violations
  inputs:
    targetType: 'inline'
    script: |
      # 读取Mend扫描结果文件
      $scanResultPath = "$(Agent.TempDirectory)/whitesource/scanResult.json"
      if (Test-Path $scanResultPath) {
          $scanResult = Get-Content $scanResultPath | ConvertFrom-Json
          # 检查是否存在策略违规
          if ($scanResult.policyViolations -and $scanResult.policyViolations.count -gt 0) {
              Write-Host "##vso[task.logissue type=error]检测到Mend策略违规,共$($scanResult.policyViolations.count)项"
              Write-Host "##vso[task.complete result=Failed;]Mend策略违规"
          } else {
              Write-Host "未检测到Mend策略违规"
          }
      } else {
          Write-Host "##vso[task.logissue type=warning]未找到Mend扫描结果文件"
      }

Bash示例:

- task: Bash@3
  displayName: Check Mend Policy Violations
  inputs:
    targetType: 'inline'
    script: |
      SCAN_RESULT_PATH=$(Agent.TempDirectory)/whitesource/scanResult.json
      if [ -f "$SCAN_RESULT_PATH" ]; then
          VIOLATION_COUNT=$(jq '.policyViolations | length' "$SCAN_RESULT_PATH")
          if [ "$VIOLATION_COUNT" -gt 0 ]; then
              echo "##vso[task.logissue type=error]检测到Mend策略违规,共$VIOLATION_COUNT项"
              echo "##vso[task.complete result=Failed;]Mend策略违规"
          else
              echo "未检测到Mend策略违规"
          fi
      else
          echo "##vso[task.logissue type=warning]未找到Mend扫描结果文件"
      fi

关键说明:使用Azure DevOps任务命令##vso[task.complete]强制标记构建失败,同时保留Mend任务生成的报告标签页。

3. 确保报告始终可访问

  • 上述配置中,Mend任务已设置report.generate=true,扫描完成后会自动在Azure DevOps构建页面生成"Mend"标签页,无论后续脚本是否触发构建失败。
  • 若报告未显示,可检查Mend任务的report.outputDirectory配置,确保报告生成在流水线工作目录下(默认会被Azure DevOps捕获)。

完整流水线片段示例

steps:
  # 前置构建步骤(如还原依赖)
  - task: NuGetCommand@2
    displayName: 'Restore NuGet Packages'
    inputs:
      command: 'restore'
      restoreSolution: '**/*.sln'

  # Mend扫描任务
  - task: WhiteSource@21
    displayName: Run Mend Scanning on L&R API
    inputs:
      projectName: "$(Build.Repository.Name)"
      configuration: |
        resolveAllDependencies=false
        nuget.resolveDependencies=true
        nuget.resolvePackagesConfigFiles=false
        nuget.resolveCsProjFiles=true
        nuget.resolveNuspecFiles=true
        nuget.resolveAssetsFiles=false
        nuget.runPreStep=true
        nuget.preferredEnvironment=nuget
        checkPolicies=true
        forceCheckAllDependencies=true
        updateInventory=true
        forceUpdate=true
        forceUpdate.failBuildOnPolicyViolation=false
        report.generate=true
        report.format=html
        scanComment=Azure DevOps pipeline build scan
        includes=**/*.dll **/*.cs **/*.nupkg

  # 检查违规并触发失败
  - task: PowerShell@2
    displayName: Check Mend Policy Violations
    inputs:
      targetType: 'inline'
      script: |
        $scanResultPath = "$(Agent.TempDirectory)/whitesource/scanResult.json"
        if (Test-Path $scanResultPath) {
            $scanResult = Get-Content $scanResultPath | ConvertFrom-Json
            if ($scanResult.policyViolations -and $scanResult.policyViolations.count -gt 0) {
                Write-Host "##vso[task.logissue type=error]检测到Mend策略违规,共$($scanResult.policyViolations.count)项"
                Write-Host "##vso[task.complete result=Failed;]Mend策略违规"
            }
        } else {
            Write-Host "##vso[task.logissue type=warning]未找到Mend扫描结果文件"
        }

内容的提问来源于stack exchange,提问作者Adam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 18:10:33