Sonatype for Azure DevOps

Sonatype for Azure DevOps

The Sonatype for Azure DevOps extension integrates with the Azure DevOps pipeline to run policy evaluations in the build workspace. It adds a new step within the build, during which Sonatype IQ Server scans applications to identify any open-source security, license, or quality policy violations. It can be configured to fail the build or generate a warning. This allows the build maintainers to understand the reasons for build failures and plan a remediation strategy.

This extension wraps the Sonatype IQ CLI.

The Sonatype for Azure DevOps extension is available on the Visual Studio Marketplace.

Main Features

Release Notes

iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.

iq-azure-devops

Changelog

Version 2.13.1 (July 08, 2026) Anchor

Version 2.13.0 (July 08, 2026) Anchor

Version 2.12.0 (June 05, 2026) Anchor

Version 2.11.0 (May 07, 2026) Anchor

Version 2.10.0 (April 10, 2026) Anchor

Version 2.9.2 (March 06, 2026) Anchor

Version 2.9.1 (February 10, 2026) Anchor

Version 2.9.0 (February 10, 2026) Anchor

Version 2.8.2 (December 17, 2025) Anchor

Version 2.8.1 (December 05, 2025) Anchor

Version 2.8.0 (November 07, 2025) Anchor

Version 2.7.0 (October 09, 2025) Anchor

Version 2.6.3 (September 12, 2025) Anchor

Version 2.6.2 (August 15, 2025) Anchor

Version 2.6.1 (August 15, 2025) Anchor

Version 2.6.0 (July 11, 2025) Anchor

Version 2.5.0 (June 12, 2025) Anchor

Version 2.4.3 (May 12, 2025) Anchor

Version 2.4.2 (April 29, 2025) Anchor

Version 2.4.1 (April 24, 2025) Anchor

Version 2.4.0 (April 22, 2025) Anchor

Version 2.3.2 (April 03, 2025) Anchor

Version 2.3.1 (March 11, 2025) Anchor

Version 2.3.0 (March 06, 2025) Anchor

Version 2.2.0 (February 18, 2025) Anchor

Version 2.1.0 (February 05, 2025) Anchor

Version 2.0.6 (January 09, 2025) Anchor

Version 2.0.5 (December 10, 2024) Anchor

Version 2.0.4 (November 08, 2024) Anchor

Version 2.0.3 (October 11, 2024) Anchor

Version 2.0.2 (September 04, 2024) Anchor

Version 2.0.1 (August 20, 2024) Anchor

Version 2.0.0 (August 13, 2024) Anchor

Version 1.7.21 (August 12, 2024) Anchor

Version 1.7.20 (August 08, 2024) Anchor

Version 1.7.19 (July 11, 2024) Anchor

Version 1.7.18 (June 26, 2024) Anchor

Version 1.7.17 (June 4, 2024) Anchor

Version 1.7.16 (May 15, 2024) Anchor

Version 1.7.15 (April 25, 2024) Anchor

Version 1.7.14 (April 9, 2024) Anchor

Version 1.7.13 (March 6, 2024) Anchor

Version 1.7.12 (February 7, 2024) Anchor

Version 1.7.11 (January 22, 2024) Anchor

Version 1.7.10 (December 11, 2023) Anchor

Version 1.7.9 Anchor

Version 1.7.8 Anchor

Version 1.7.7 Anchor

Version 1.7.6 Anchor

Version 1.7.5 Anchor

Version 1.7.4 Anchor

Version 1.7.3 Anchor

Version 1.7.2 Anchor

Version 1.7.1 Anchor

Version 1.7.0 Anchor

Version 1.6.9 Anchor

Version 1.6.8 Anchor

Version 1.6.7 Anchor

Version 1.6.6 Anchor

Version 1.6.5 Anchor

Version 1.6.4 Anchor

Version 1.6.3 Anchor

Version 1.6.2 Anchor

Version 1.6.1 Anchor

Version 1.5.7 Anchor

Version 1.5.6 Anchor

Version 1.5.5 Anchor

Version 1.5.4 Anchor

Version 1.5.2 Anchor

Version 1.5.0 Anchor

Version 1.4.0 Anchor

Version 1.3.35 Anchor

Version 1.3.34 Anchor

Version 1.3.33 Anchor

Version 1.3.32 Anchor

Version 1.3.31 Anchor

Version 1.3.30 Anchor

Version 1.3.28 Anchor

Version 1.3.27 Anchor

Version 1.3.26 Anchor

Version 1.3.25 Anchor

Version 1.3.24 Anchor

Version 1.3.23 Anchor

Version 1.3.22 Anchor

Version 1.3.19 Anchor

Version 1.3.18 Anchor

Version 1.3.17 Anchor

Version 1.3.16 Anchor

Version 1.3.15 Anchor

Version 1.3.14 Anchor

Version 1.3.13 Anchor

Version 1.3.12 Anchor

Version 1.3.11 Anchor

Version 1.3.10 Anchor

Version 1.3.9 Anchor

Version 1.3.8 Anchor

Version 1.3.7 Anchor

Version 1.3.6 Anchor

Version 1.3.5 Anchor

Version 1.3.4 Anchor

Version 1.3.3 Anchor

Version 1.3.2 Anchor

Version 1.3.1 Anchor

Version 1.3.0 Anchor

Version 1.2.15 Anchor

Version 1.2.14 Anchor

Version 1.2.13 Anchor

Version 1.2.12 Anchor

Version 1.2.11 Anchor

Version 1.2.10 Anchor

Version 1.2.9 Anchor

Version 1.2.8 Anchor

Version 1.2.7 Anchor

Version 1.2.6 Anchor

Version 1.2.5 Anchor

Version 1.2.4 Anchor

Version 1.2.3 Anchor

Version 1.2.2 Anchor

Compatibility

iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.

iq-azure-devops

Compatibility

The organization ID parameter requires at least version 1.5.0 of the plugin and IQ Server 143 or higher

Plugin Version IQ Server Version Azure DevOps Version Java Runtime
2.0.0 and newer 180 and higher Azure DevOps Services (hosted) Java 17
Azure DevOps Server 2019
1.2.0 to 1.7.21 66 and higher Azure DevOps Services (hosted) JDK 8, JDK 11
Azure DevOps Server 2019
1.0.0 to 1.1.0 66 and higher Azure DevOps Services (hosted) JDK 8, JDK 11

Installation and Configuration

Go to the Installation and Configuration page for steps to install and set up Sonatype IQ in your Azure DevOps pipelines.

Evaluating Policies

The "SonatypeEvaluate" task appears in the jobs list during a build:

Accessing/Viewing Results

Open SonatypeEvaluate to view a console output with the results of the evaluation:

The console output contains a summary of the policy evaluation and a link to the detailed report in IQ Server.

Select the Sonatype IQ Summary Report tab on the build to see a summary report of the policy evaluation for the scanned components:

Select the Sonatype IQ Build Report tab on the build for a detailed report with all the components and their correspondent violations:

If reachability analysis is enabled, select the Sonatype IQ Reachability Analysis tab for a detailed report of components with vulnerable methods and which of those methods are actually reachable in your code. This tab also lets you navigate, at the component level, between the Reachability Analysis and Build Report tabs.

Note

NexusIqPipelineTask is still supported but has been deprecated and may be removed in a future version. The embedded IQ CLI has been removed from the extension package; the task now downloads the latest CLI automatically at runtime. If you need to pin a specific CLI version, use the SonatypeEvaluate task instead. See Installation and Configuration for details.

SARIF File Generation

When the sarifFile input parameter is set, the SonatypeEvaluate task will emit a SARIF report named as you specify, containing all identified vulnerabilities. The path to the generated file is exposed via the task’s sarifFile output variable, which you can reference in downstream steps.

You can then publish that SARIF file as a pipeline artifact with the PublishBuildArtifacts task and view it in your build summary by installing the SARIF SAST Scans Tab extension, which adds a Scans tab to the build results UI.

Here’s an example pipeline snippet:

- task: SonatypeEvaluate@2 name: sonatypePolicyEvaluation inputs: nexusIqService: 'IQ-SERVICE-CONNECTION' applicationId: 'app-01' stage: 'Build' scanTargets: '**/target/*.jar' sarifFile: 'result.sarif'
task: PublishBuildArtifacts@1
inputs:
PathtoPublish: '$(sonatypePolicyEvaluation.sarifFile)'
ArtifactName: 'CodeAnalysisLogs'
publishLocation: 'Container'
condition: succeededOrFailed()

After your pipeline completes, open the Scans tab on the build summary to review the vulnerabilities in the SARIF report.

Add dashboard widgets for Sonatype IQ

For ease of use, the following widgets for Sonatype IQ can be added to the Azure DevOps dashboard.

  1. Sonatype IQ Policy Evaluation widget: shows the policy evaluation results for the latest build.
  2. Trends for Sonatype IQ Policy Evaluation: shows a historical trend of Sonatype IQ Policy evaluations of the last 5 builds.

How to add Sonatype IQ widgets to the Azure DevOps Dashboard:

  1. Go to "Overview" → "Dashboards" and click the "Edit" button.

  2. On the right-hand side, under "Add Widget", search for "Sonatype IQ":

  3. Select the appropriate widget and click the "Add" button at the bottom right corner of the page. Click the "Done editing" button.

  4. Sonatype IQ widget now displays the dashboard showing the results summary for the latest build and the historical summary for the last 5 builds.

Running Sonatype IQ in Azure Self-Hosted Agents

If you’re using an HTTP proxy within your infrastructure and Azure self-hosted build agents, you can specify the Azure DevOps agent’s proxy settings. These settings will then be automatically applied when connecting to IQ. For more information, refer to Microsoft’s documentation.

In the Azure-provided sample command:

./config.sh --proxyurl http://127.0.0.1:8888 --proxyusername "myuser" --proxypassword "mypass"

This would appear in the scan output as it is passed through to the IQ scan client:

...
-p
127.0.0.1:8888
-U
myuser:***
...

Fetch SBOM Task Properties

Fetch SBOM is a task for retrieving an SBOM (Software Bill of Materials) file associated with a previous Lifecycle evaluation. It supports both the CycloneDX and SPDX standards. For configuration steps, see the Installation and Configuration page.

Parameter Required/Optional Description
nexusIqService Required Sonatype IQ service connection to use.
applicationId Required Must match the applicationId used in the preceding Evaluation task.
scanId Required Scan identifier produced by the Evaluation step. Pass it as $(<evaluation-reference-name>.scanId).
sbomStandard Required SBOM standard: spdx or cyclonedx.
sbomVersion Optional Version of the SBOM standard. Available CycloneDX versions: 1.2, 1.3, 1.4, 1.5, 1.6. Default version for CycloneDX is 1.6. Available SPDX versions: 2.2, 2.3. Default version for SPDX is 2.3.
sbomFormat Optional Output file format: json or xml. Default: json.
acceptIqServerSelfSignedCertificates Optional Accept self-signed TLS certificates from IQ Server. Default: false.

Note

The reference name you assign to each task (e.g., sonatypePolicyEvaluation, sonatypeFetchSbomTask) becomes the prefix for its output variables. Adjust the variable references accordingly.

Reachability Analysis

See Reachability Analysis with Sonatype for Azure DevOps for how to enable Reachability in Java/JVM builds covering required permissions, the parameters, a usage example, and the default entry point strategy with tips on narrowing scope via namespaces.

Git/jgit Configuration and Permissions

The Azure DevOps extension uses the Sonatype IQ CLI to perform scans.

During the scanning process, the CLI uses Git to detect the repository URL, commit hash, and branch name.

If native Git is available on the build agent, the CLI will use it; otherwise, it falls back to jgit (Java-based Git). When jgit is used, it attempts to create configuration files in the current user’s $HOME directory. If it doesn’t have permission to do so, you may see ERROR-level log messages—these are not critical to the scan and can be safely ignored. To avoid them, make sure native Git is installed on the build agent, or set the XDG_CONFIG_HOME environment variable to a directory that the build agent user can write to.

Exit Codes

The pipelines emit the following exit codes:

Exit Code Description
0 Success
1 Policy violation
2 Scanning error
3 Reachability error
4 Configuration error
5 Connectivity error
6 Local I/O error
7 Authentication error

The pipelines now emit the following output variables:

Variable Description
CliExitCode Numeric exit code returned by the CLI.
CliExitCategory Category name of the exit code.
CliExitMessage Detailed error or success message.

Usage example:

steps:
- task: SonatypeEvaluate@2
 name: iqEval
 displayName: 'Sonatype IQ policy evaluation'
 inputs:
 nexusIqService: 'nexus-iq-lifecycle'
 applicationId: 'an-application'
 scanTargets: pom.xml
 condition: succeededOrFailed()
- bash: |
 echo "CliExitCode: $(iqEval.CliExitCode)"
 echo "CliExitCategory: $(iqEval.CliExitCategory)"
 echo "CliExitMessage: $(iqEval.CliExitMessage)"
 displayName: 'Print Sonatype IQ task exit variables'
 condition: succeededOrFailed()

Centralized CI configuration

To centrally manage supported CI evaluation settings for Azure DevOps pipelines through the Lifecycle organization and application hierarchy, see the CI Configuration REST API.

Search results

No results found