Skip to content

Update FoD pipeline to use "fcli action run ci"#54

Open
kadraman wants to merge 2 commits intomainfrom
azure-pipelines-fod-update
Open

Update FoD pipeline to use "fcli action run ci"#54
kadraman wants to merge 2 commits intomainfrom
azure-pipelines-fod-update

Conversation

@kadraman
Copy link
Collaborator

No description provided.

Copilot AI review requested due to automatic review settings February 26, 2026 16:12
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Azure DevOps Fortify on Demand (FoD) SAST pipeline template to run the Fortify CI “action” flow (fcli action run ci) instead of using the legacy FortifyOnDemandStatic@8 Azure DevOps task.

Changes:

  • Adds explicit checkout configuration (clean workspace + persisted credentials).
  • Replaces the FoD Azure DevOps task with Bash steps that install Fortify tooling via npx @fortify/setup and run fcli action run ci.
  • Introduces FoD-related pipeline variable documentation and wires those variables into the scan step via env:.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@kadraman kadraman requested a review from rsenden February 26, 2026 16:30
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fortify vulnerability summary

Any issues listed below are based on comparing the latest scan results against the previous scan results in FoD release fortify/IWA-Java - azure-pipelines-fod-update. This is for informational purposes only and, depending on workflow, may not be an accurate representation of what issues will be introduced into or removed from the target branch when merging this PR.

New Issues

  • No new or re-introduced issues were detected

Removed Issues

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants