Reachability Analysis with Sonatype for Azure DevOps

Reachability Analysis with Sonatype for Azure DevOps

You can configure Sonatype for Azure DevOps to perform Reachability Analysis, which can detect method signatures in your application code that contain components with potentially exploitable security vulnerabilities. Policy violations occurring due to these vulnerable components are labeled as Reachable and can be viewed on the application report.

By including additional parameters in the pipeline tasks you can enable the Reachability Analysis feature. The scan process will then analyze application code and dependencies in the scan target for Java (or any JVM language), JavaScript/TypeScript, and .NET projects. This allows you to detect reachable vulnerabilities, even in proprietary components within your application.

Permissions Required

Sonatype for Azure DevOps users should have the Evaluate Applications permissions to scan applications with Reachability Analysis.

Ignoring Reachability Analysis Errors

If this setting is checked, reachability execution failures do not impact the build status. Otherwise, the build is marked as FAILED.

Using Java Reachability Analysis

Both the Sonatype Evaluate task and the Sonatype for Azure DevOps task expose parameters to enable Java Reachability Analysis:

You can use regular expressions when specifying the namespace. Example: For org.foo.example, you can use regular expressions with '/' at the start and end of the string as /^org\.+.*\.example/

The same parameters can be used in a scripted pipeline, as in the example below:

- task: SonatypeEvaluate@2
  inputs:  # other input parameters could be provided here
    enableReachability: true
    reachabilityNamespaces: 'com.example.library.one com.example.app.two'
    reachabilityEntrypointStrategy: CONCRETE  # more input parameters may follow

Entrypoint Strategy

The entrypoint strategy determines which methods are treated as entry points for your application.

The default entrypoint strategy is CONCRETE, which means every non-abstract, non-synthetic method defined in a non-interface, non-annotation class is considered a potential entry point. Use the Java Reachability namespaces parameter (described above) to restrict the method set to specific namespaces and improve the overall results.

Using JavaScript Reachability Analysis

Both the Sonatype Evaluate task and the Sonatype for Azure DevOps task expose parameters to enable JavaScript Reachability Analysis.

The same parameters can be used in a scripted pipeline, as in the example below:

- task: SonatypeEvaluate@2
  inputs:
    applicationId: 'myapp'
    scanTargets: 'package-lock.json'
    enableReachabilityJs: true
    reachabilityJsSources: 'src/**/*.js'
    reachabilityJsExcludes: 'src/test/**/*.js'
    reachabilityJsProjectRoot: '.'

Using .NET Reachability Analysis

.NET reachability is supported in Sonatype for Azure DevOps 2.12.0 and later.

Both the Sonatype Evaluate task and the Sonatype for Azure DevOps task expose parameters to enable .NET Reachability Analysis.

The same parameters can be used in a scripted pipeline, as in the example below:

- task: SonatypeEvaluate@2
  inputs:
    applicationId: 'myapp'
    scanTargets: '*.dll'
    enableReachabilityDotNet: true
    reachabilityDotNetNamespaces: MyCompany.App
    reachabilityDotNetEntrypointStrategy: 'DOTNET_MAIN'
    reachabilityDotNetPath: /opt/bin/dotnet

Search results

No results found.