如何在Azure DevOps实现Release分支PR前的Develop分支合并验证
在Azure DevOps实现Release分支PR的前置合并验证
核心思路
通过Build Validation + PowerShell脚本调用Azure DevOps API,在PR提交到Release分支时自动检查:当前PR的源分支是否已通过合并PR并入Develop分支,未满足则阻断PR合并。
详细实现步骤
一、创建用于验证的Build Pipeline
- 进入Azure DevOps项目的Pipelines页面,点击新建流水线
- 选择使用经典编辑器(或YAML,两种方式均支持),关联你的代码仓库后选择空作业
- 添加PowerShell任务:
- 在作业中点击**+,搜索并添加PowerShell**任务
- 设置任务为内联脚本,粘贴后续的验证脚本
二、PowerShell验证脚本(核心逻辑)
# 配置项目参数 $orgUrl = "https://dev.azure.com/你的组织名" $projectName = "你的项目名" $targetDevelopBranch = "refs/heads/develop" $allowedReleaseBranches = @("refs/heads/release", "refs/heads/release/*") # 匹配你的Release分支规则 # 获取PR上下文信息(Build Validation触发时自动注入) $prId = $(System.PullRequest.PullRequestId) $sourceBranch = $(System.PullRequest.SourceBranch) $targetBranch = $(System.PullRequest.TargetBranch) # 跳过非Release分支的PR检查 if (-not $allowedReleaseBranches.Contains($targetBranch) -and -not $targetBranch -like "refs/heads/release/*") { Write-Host "目标分支非Release分支,跳过验证" exit 0 } # 允许从Develop分支直接提PR到Release if ($sourceBranch -eq $targetDevelopBranch) { Write-Host "源分支为Develop,直接通过验证" exit 0 } # 调用API查询源分支是否有合并到Develop的已完成PR $apiUrl = "$orgUrl/$projectName/_apis/git/pullrequests?searchCriteria.sourceRefName=$sourceBranch&searchCriteria.targetRefName=$targetDevelopBranch&searchCriteria.status=completed&api-version=7.1-preview.1" # 使用Pipeline内置令牌鉴权,无需手动配置PAT $headers = @{ "Authorization" = "Bearer $(System.AccessToken)" } try { $response = Invoke-RestMethod -Uri $apiUrl -Headers $headers -Method Get -ContentType "application/json" if ($response.count -eq 0) { Write-Error "错误:当前源分支[$sourceBranch]未合并到Develop分支,请先提交PR到Develop并合并后再提Release分支PR" exit 1 } else { Write-Host "验证通过:源分支[$sourceBranch]已合并到Develop分支" exit 0 } } catch { Write-Error "API请求失败:$($_.Exception.Message)" exit 1 }
三、配置Pipeline权限
确保Pipeline服务账号有权限读取Pull Requests:
- 进入项目设置 -> 权限 -> Repositories
- 找到Project Collection Build Service (你的组织名),设置其权限为Contributor(或至少赋予读取Pull Requests权限)
四、关联到Release分支的分支策略
- 进入项目的Repos -> Branches
- 找到你的Release分支,点击右侧**...** -> 分支策略
- 在生成验证部分,点击添加:
- 选择刚才创建的验证Pipeline
- 设置触发条件为创建PR时和每次更新PR时
- 勾选阻塞合并,确保验证失败时无法合并PR
- 按需设置过期时间和适用的PR创建者
YAML版本Pipeline示例
如果偏好YAML管理Pipeline,可使用以下内容创建YAML文件并关联:
trigger: none # 禁止自动触发,仅在PR时触发 pr: branches: include: - release/* # 仅针对Release分支的PR触发 exclude: - develop - main pool: vmImage: 'windows-latest' steps: - task: PowerShell@2 inputs: targetType: 'inline' script: | # 复制上述PowerShell脚本内容到这里 $orgUrl = "https://dev.azure.com/你的组织名" $projectName = "你的项目名" $targetDevelopBranch = "refs/heads/develop" $allowedReleaseBranches = @("refs/heads/release", "refs/heads/release/*") $prId = $(System.PullRequest.PullRequestId) $sourceBranch = $(System.PullRequest.SourceBranch) $targetBranch = $(System.PullRequest.TargetBranch) if (-not $allowedReleaseBranches.Contains($targetBranch) -and -not $targetBranch -like "refs/heads/release/*") { Write-Host "目标分支非Release分支,跳过验证" exit 0 } if ($sourceBranch -eq $targetDevelopBranch) { Write-Host "源分支为Develop,直接通过验证" exit 0 } $apiUrl = "$orgUrl/$projectName/_apis/git/pullrequests?searchCriteria.sourceRefName=$sourceBranch&searchCriteria.targetRefName=$targetDevelopBranch&searchCriteria.status=completed&api-version=7.1-preview.1" $headers = @{ "Authorization" = "Bearer $(System.AccessToken)" } try { $response = Invoke-RestMethod -Uri $apiUrl -Headers $headers -Method Get -ContentType "application/json" if ($response.count -eq 0) { Write-Error "错误:当前源分支[$sourceBranch]未合并到Develop分支,请先提交PR到Develop并合并后再提Release分支PR" exit 1 } else { Write-Host "验证通过:源分支[$sourceBranch]已合并到Develop分支" exit 0 } } catch { Write-Error "API请求失败:$($_.Exception.Message)" exit 1 }
内容的提问来源于stack exchange,提问作者anwar31dz
相关产品推荐
相关产品推荐

