Sonatype for Azure DevOps
Sonatype for Azure DevOps
The Sonatype for Azure DevOps extension integrates with the Azure DevOps pipeline to run policy evaluations in the build workspace. It adds a new step within the build, during which Sonatype IQ Server scans applications to identify any open-source security, license, or quality policy violations. It can be configured to fail the build or generate a warning. This allows the build maintainers to understand the reasons for build failures and plan a remediation strategy.
This extension wraps the Sonatype IQ CLI.
The Sonatype for Azure DevOps extension is available on the Visual Studio Marketplace.
Main Features
- Perform a Sonatype IQ Server policy evaluation on files in the build workspace.
- Display scan results within Azure DevOps pipeline report.
- Provide a link to a comprehensive Sonatype Lifecycle policy evaluation report indicating violation details and remediation recommendations.
Release Notes
iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.
iq-azure-devops
Changelog
Version 2.13.1 (July 08, 2026) Anchor
- Fixed a regression that caused all policy evaluations to fail with “Cannot read properties of undefined (reading ‘retrieveSecret’)
Version 2.13.0 (July 08, 2026) Anchor
- Introduced granular exit codes
- Enhanced results cleanup to prevent stale information from displaying in the UI
- Improved support for HTTP proxy configuration in pipeline tasks
Version 2.12.0 (June 05, 2026) Anchor
- Added support for .NET reachability analysis
- Added support for reachability analysis evidence
Version 2.11.0 (May 07, 2026) Anchor
- Updated the IQ CLI to be dynamically downloaded at runtime instead of being bundled within the extension
- Fixed an issue where proprietary component regex patterns were not being processed correctly
Version 2.10.0 (April 10, 2026) Anchor
- Added support for API-based CI configuration
- Added support for Sonatype Container Scanner
Version 2.9.2 (March 06, 2026) Anchor
- Maintenance release
Version 2.9.1 (February 10, 2026) Anchor
- Maintenance release
Version 2.9.0 (February 10, 2026) Anchor
- Added support for JavaScript reachability analysis
- Implemented security controls for the “IQ CLI Download URL” parameter in the Sonatype Evaluate task
- Added basic authentication support for “IQ CLI Download URL” parameter
- Sonatype IQ build tabs are no longer visible when pipeline doesn’t contain any Sonatype tasks
Version 2.8.2 (December 17, 2025) Anchor
- Maintenance release
Version 2.8.1 (December 05, 2025) Anchor
- Fixed an edge case where scans failed for npm projects
Version 2.8.0 (November 07, 2025) Anchor
- Added support for npm workspaces
- Improved scan performance for pnpm-lock.yaml files
Version 2.7.0 (October 09, 2025) Anchor
- Added support for Docker Client v28 in Docker Image Analysis
- Added support for scanning pnpm-lock.yaml v9 manifest files
Version 2.6.3 (September 12, 2025) Anchor
- Added support for analyzing Java 25 bytecode
Version 2.6.2 (August 15, 2025) Anchor
- Maintenance release
Version 2.6.1 (August 15, 2025) Anchor
- Added support for analyzing Java 23 and Java 24 bytecode
Version 2.6.0 (July 11, 2025) Anchor
- Added SARIF file generation capability
- Added new Reachability Analysis tab
Version 2.5.0 (June 12, 2025) Anchor
- Added support for SBOM generation
- Added support for publishing evaluation results as a pipeline artifact
- Added support to view multiple application-evaluation summaries in the ‘Sonatype IQ Summary Report’ tab
- Added support for IQ Server self-signed certificates
- Fixed issue with broken ‘Developer Priorities’ report link
Version 2.4.3 (May 12, 2025) Anchor
- Improved pipeline status visibility in the extension tabs
Version 2.4.2 (April 29, 2025) Anchor
- Fixed a Reachability Analysis compatibility issue with previous IQ Server versions
Version 2.4.1 (April 24, 2025) Anchor
- Fixed a webpack bundler issue affecting the
SonatypeEvaluatetask
Version 2.4.0 (April 22, 2025) Anchor
- Added
SonatypeEvaluatetask to run policy evaluations using any version of the Sonatype IQ CLI - Fixed an issue affecting
ignoreScanningErrorandignoreSystemErrorparameters - Added new reachability parameters (
enableReachabilityandreachabilityNamespaces) to replace the previous options (enableCallflowandcallflowNamespaces)
Version 2.3.2 (April 03, 2025) Anchor
- Updated the ‘ignoreScanningError’ input to allow scans to continue even if some files can’t be accessed
Version 2.3.1 (March 11, 2025) Anchor
- Fixed Node 20 runtime not being utilized as intended in pipelines
- Fixed handling of IQ Server connectivity when a trailing slash existed in the URL
Version 2.3.0 (March 06, 2025) Anchor
- Added Priorities URL to the scan result
- Added Priorities URL to the widget views
Version 2.2.0 (February 18, 2025) Anchor
- Added support for reachability analysis in Java (or any JVM language) binaries found in the scan targets to identify method signatures that trigger security vulnerabilities
- Fixed an issue that prevented components from being identified when scanning a
pom.xmlwith missing nested component values - Updated the extension’s name, logos, and documentation to improve the look and feel
Version 2.1.0 (February 05, 2025) Anchor
- Added branch name collection when a scan runs in a Git repository context
Version 2.0.6 (January 09, 2025) Anchor
- Updated the pipeline task to be compatible with Node 20, resolving issues with Azure DevOps agents
Version 2.0.5 (December 10, 2024) Anchor
- Maintenance release
Version 2.0.4 (November 08, 2024) Anchor
- Maintenance release
Version 2.0.3 (October 11, 2024) Anchor
- Maintenance release
Version 2.0.2 (September 04, 2024) Anchor
- Maintenance release
Version 2.0.1 (August 20, 2024) Anchor
- Maintenance release
Version 2.0.0 (August 13, 2024) Anchor
- Java 17 is now required to execute the
NexusIqPipelineTask
Version 1.7.21 (August 12, 2024) Anchor
- Updated internal dependencies so Java 17 is not required to run the plugin
Version 1.7.20 (August 08, 2024) Anchor
- Maintenance release
Version 1.7.19 (July 11, 2024) Anchor
- Maintenance release
Version 1.7.18 (June 26, 2024) Anchor
- Maintenance release
Version 1.7.17 (June 4, 2024) Anchor
- Maintenance release
Version 1.7.16 (May 15, 2024) Anchor
- Maintenance release
Version 1.7.15 (April 25, 2024) Anchor
- Made NexusIqPipelineTask work on agents running on Node 16
Version 1.7.14 (April 9, 2024) Anchor
- Maintenance release
Version 1.7.13 (March 6, 2024) Anchor
- Maintenance release
Version 1.7.12 (February 7, 2024) Anchor
- Maintenance release
Version 1.7.11 (January 22, 2024) Anchor
- Maintenance release
Version 1.7.10 (December 11, 2023) Anchor
- Maintenance release
Version 1.7.9 Anchor
- Maintenance release
Version 1.7.8 Anchor
- Maintenance release
Version 1.7.7 Anchor
- Naming updates for legacy violations
Version 1.7.6 Anchor
- Maintenance release
Version 1.7.5 Anchor
- Maintenance release
Version 1.7.4 Anchor
- Optionally use the $(Pipeline.Workspace) folder as a base for scanning
Version 1.7.3 Anchor
- Maintenance release
Version 1.7.2 Anchor
- Maintenance release
Version 1.7.1 Anchor
- Maintenance release
Version 1.7.0 Anchor
- Maintenance release
Version 1.6.9 Anchor
- Maintenance release
Version 1.6.8 Anchor
- Maintenance release
Version 1.6.7 Anchor
- Maintenance release
Version 1.6.6 Anchor
- Maintenance release
Version 1.6.5 Anchor
- Maintenance release
Version 1.6.4 Anchor
- Maintenance release
Version 1.6.3 Anchor
- Maintenance release
Version 1.6.2 Anchor
- Maintenance release
Version 1.6.1 Anchor
- Maintenance release
Version 1.5.7 Anchor
- Maintenance release
Version 1.5.6 Anchor
- Maintenance release
Version 1.5.5 Anchor
- Maintenance release
Version 1.5.4 Anchor
- Fixed Nexus IQ Build Report to properly show the icon for “notify” actions
Version 1.5.2 Anchor
- Maintenance release
Version 1.5.0 Anchor
- Added the organization ID parameter, used for automatic IQ apps
Version 1.4.0 Anchor
- Added a task option to enable debug logging for IQ Policy Evaluations
- Improved the summary message for policy evaluations
- Added a new Nexus IQ Summary Report tab on Build view
Version 1.3.35 Anchor
- Maintenance release
Version 1.3.34 Anchor
- Maintenance release
Version 1.3.33 Anchor
- Maintenance release
Version 1.3.32 Anchor
- Maintenance release
Version 1.3.31 Anchor
- Maintenance release
Version 1.3.30 Anchor
- Maintenance release
Version 1.3.28 Anchor
- Maintenance release
Version 1.3.27 Anchor
- Maintenance release
Version 1.3.26 Anchor
- Maintenance release
Version 1.3.25 Anchor
- Maintenance release
Version 1.3.24 Anchor
- Maintenance release
Version 1.3.23 Anchor
- Maintenance release
Version 1.3.22 Anchor
- Maintenance release
Version 1.3.19 Anchor
- Maintenance release
Version 1.3.18 Anchor
- Maintenance release
Version 1.3.17 Anchor
- Maintenance release
Version 1.3.16 Anchor
- Bug fix: Correctly show a long app id in dashboard widget
Version 1.3.15 Anchor
- Maintenance release
Version 1.3.14 Anchor
- Maintenance release
Version 1.3.13 Anchor
- FIX: Correctly handle Multiple javaSystemProperties configuration
Version 1.3.12 Anchor
- FIX: Corrected null ‘match’ error when handling javaSystemProperties configuration
Version 1.3.11 Anchor
- Added support for handling Multiple javaSystemProperties configuration
Version 1.3.10 Anchor
- Maintenance release
Version 1.3.9 Anchor
- Maintenance release
Version 1.3.8 Anchor
- Maintenance release
Version 1.3.7 Anchor
- Maintenance release
Version 1.3.6 Anchor
- Maintenance release
Version 1.3.5 Anchor
- Maintenance release
Version 1.3.4 Anchor
- Maintenance release
Version 1.3.3 Anchor
- Bug fix: Correctly handle system errors such as IQ connection failures and mark the build as failed or unstable
Version 1.3.2 Anchor
- Added support for http proxy configuration on Azure Pipeline Agents.
Version 1.3.1 Anchor
- FIX: Reverted http proxy configuration support introduced in 1.3.0
Version 1.3.0 Anchor
- Added support for http proxy configuration on Azure Pipeline Agents
Version 1.2.15 Anchor
- Maintenance release
Version 1.2.14 Anchor
- Maintenance release
Version 1.2.13 Anchor
- Started sending component paths to the IQ Server, so they can be shown on Occurrences tab of reports.
- Accommodated expanded output of IQ CLI and larger numbers of artifacts
Version 1.2.12 Anchor
- FIX: Reverted 1.2.11 release to alleviate a regression while scanning larger numbers of artifacts.
Version 1.2.11 Anchor
- Started sending component paths to the IQ Server, so they can be shown on Occurrences tab of reports.
Version 1.2.10 Anchor
- Added the Artifact Staging Directory as another lookup location for scan artifacts, in addition to the Default Working Directory
Version 1.2.9 Anchor
- Maintenance release
Version 1.2.8 Anchor
- Provided a reminder on a pipeline to enable Nexus IQ for each project when it’s not already
Version 1.2.7 Anchor
- Maintenance release
Version 1.2.6 Anchor
- Maintenance release
Version 1.2.5 Anchor
- Maintenance release
Version 1.2.4 Anchor
- Maintenance release
Version 1.2.3 Anchor
- Maintenance release
Version 1.2.2 Anchor
- Maintenance release
Compatibility
iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.
iq-azure-devops
Compatibility
The organization ID parameter requires at least version 1.5.0 of the plugin and IQ Server 143 or higher
| Plugin Version | IQ Server Version | Azure DevOps Version | Java Runtime |
|---|---|---|---|
| 2.0.0 and newer | 180 and higher | Azure DevOps Services (hosted) | Java 17 |
| Azure DevOps Server 2019 | |||
| 1.2.0 to 1.7.21 | 66 and higher | Azure DevOps Services (hosted) | JDK 8, JDK 11 |
| Azure DevOps Server 2019 | |||
| 1.0.0 to 1.1.0 | 66 and higher | Azure DevOps Services (hosted) | JDK 8, JDK 11 |
Installation and Configuration
Go to the Installation and Configuration page for steps to install and set up Sonatype IQ in your Azure DevOps pipelines.
Evaluating Policies
The "SonatypeEvaluate" task appears in the jobs list during a build:
Accessing/Viewing Results
Open SonatypeEvaluate to view a console output with the results of the evaluation:
The console output contains a summary of the policy evaluation and a link to the detailed report in IQ Server.
Select the Sonatype IQ Summary Report tab on the build to see a summary report of the policy evaluation for the scanned components:
Select the Sonatype IQ Build Report tab on the build for a detailed report with all the components and their correspondent violations:
If reachability analysis is enabled, select the Sonatype IQ Reachability Analysis tab for a detailed report of components with vulnerable methods and which of those methods are actually reachable in your code. This tab also lets you navigate, at the component level, between the Reachability Analysis and Build Report tabs.
Note
NexusIqPipelineTask is still supported but has been deprecated and may be removed in a future version. The embedded IQ CLI has been removed from the extension package; the task now downloads the latest CLI automatically at runtime. If you need to pin a specific CLI version, use the SonatypeEvaluate task instead. See Installation and Configuration for details.
SARIF File Generation
When the sarifFile input parameter is set, the SonatypeEvaluate task will emit a SARIF report named as you specify, containing all identified vulnerabilities. The path to the generated file is exposed via the task’s sarifFile output variable, which you can reference in downstream steps.
You can then publish that SARIF file as a pipeline artifact with the PublishBuildArtifacts task and view it in your build summary by installing the SARIF SAST Scans Tab extension, which adds a Scans tab to the build results UI.
Here’s an example pipeline snippet:
- task: SonatypeEvaluate@2 name: sonatypePolicyEvaluation inputs: nexusIqService: 'IQ-SERVICE-CONNECTION' applicationId: 'app-01' stage: 'Build' scanTargets: '**/target/*.jar' sarifFile: 'result.sarif'
task: PublishBuildArtifacts@1
inputs:
PathtoPublish: '$(sonatypePolicyEvaluation.sarifFile)'
ArtifactName: 'CodeAnalysisLogs'
publishLocation: 'Container'
condition: succeededOrFailed()
After your pipeline completes, open the Scans tab on the build summary to review the vulnerabilities in the SARIF report.
Add dashboard widgets for Sonatype IQ
For ease of use, the following widgets for Sonatype IQ can be added to the Azure DevOps dashboard.
- Sonatype IQ Policy Evaluation widget: shows the policy evaluation results for the latest build.
- Trends for Sonatype IQ Policy Evaluation: shows a historical trend of Sonatype IQ Policy evaluations of the last 5 builds.
How to add Sonatype IQ widgets to the Azure DevOps Dashboard:
Go to "Overview" → "Dashboards" and click the "Edit" button.
On the right-hand side, under "Add Widget", search for "Sonatype IQ":
Select the appropriate widget and click the "Add" button at the bottom right corner of the page. Click the "Done editing" button.
Sonatype IQ widget now displays the dashboard showing the results summary for the latest build and the historical summary for the last 5 builds.
Running Sonatype IQ in Azure Self-Hosted Agents
If you’re using an HTTP proxy within your infrastructure and Azure self-hosted build agents, you can specify the Azure DevOps agent’s proxy settings. These settings will then be automatically applied when connecting to IQ. For more information, refer to Microsoft’s documentation.
In the Azure-provided sample command:
./config.sh --proxyurl http://127.0.0.1:8888 --proxyusername "myuser" --proxypassword "mypass"
This would appear in the scan output as it is passed through to the IQ scan client:
...
-p
127.0.0.1:8888
-U
myuser:***
...
Fetch SBOM Task Properties
Fetch SBOM is a task for retrieving an SBOM (Software Bill of Materials) file associated with a previous Lifecycle evaluation. It supports both the CycloneDX and SPDX standards. For configuration steps, see the Installation and Configuration page.
| Parameter | Required/Optional | Description |
|---|---|---|
nexusIqService |
Required | Sonatype IQ service connection to use. |
applicationId |
Required | Must match the applicationId used in the preceding Evaluation task. |
scanId |
Required | Scan identifier produced by the Evaluation step. Pass it as $(<evaluation-reference-name>.scanId). |
sbomStandard |
Required | SBOM standard: spdx or cyclonedx. |
sbomVersion |
Optional | Version of the SBOM standard. Available CycloneDX versions: 1.2, 1.3, 1.4, 1.5, 1.6. Default version for CycloneDX is 1.6. Available SPDX versions: 2.2, 2.3. Default version for SPDX is 2.3. |
sbomFormat |
Optional | Output file format: json or xml. Default: json. |
acceptIqServerSelfSignedCertificates |
Optional | Accept self-signed TLS certificates from IQ Server. Default: false. |
Note
The reference name you assign to each task (e.g., sonatypePolicyEvaluation, sonatypeFetchSbomTask) becomes the prefix for its output variables. Adjust the variable references accordingly.
Reachability Analysis
See Reachability Analysis with Sonatype for Azure DevOps for how to enable Reachability in Java/JVM builds covering required permissions, the parameters, a usage example, and the default entry point strategy with tips on narrowing scope via namespaces.
Git/jgit Configuration and Permissions
The Azure DevOps extension uses the Sonatype IQ CLI to perform scans.
During the scanning process, the CLI uses Git to detect the repository URL, commit hash, and branch name.
If native Git is available on the build agent, the CLI will use it; otherwise, it falls back to jgit (Java-based Git). When jgit is used, it attempts to create configuration files in the current user’s $HOME directory. If it doesn’t have permission to do so, you may see ERROR-level log messages—these are not critical to the scan and can be safely ignored. To avoid them, make sure native Git is installed on the build agent, or set the XDG_CONFIG_HOME environment variable to a directory that the build agent user can write to.
Exit Codes
The pipelines emit the following exit codes:
| Exit Code | Description |
|---|---|
| 0 | Success |
| 1 | Policy violation |
| 2 | Scanning error |
| 3 | Reachability error |
| 4 | Configuration error |
| 5 | Connectivity error |
| 6 | Local I/O error |
| 7 | Authentication error |
The pipelines now emit the following output variables:
| Variable | Description |
|---|---|
CliExitCode |
Numeric exit code returned by the CLI. |
CliExitCategory |
Category name of the exit code. |
CliExitMessage |
Detailed error or success message. |
Usage example:
steps:
- task: SonatypeEvaluate@2
name: iqEval
displayName: 'Sonatype IQ policy evaluation'
inputs:
nexusIqService: 'nexus-iq-lifecycle'
applicationId: 'an-application'
scanTargets: pom.xml
condition: succeededOrFailed()
- bash: |
echo "CliExitCode: $(iqEval.CliExitCode)"
echo "CliExitCategory: $(iqEval.CliExitCategory)"
echo "CliExitMessage: $(iqEval.CliExitMessage)"
displayName: 'Print Sonatype IQ task exit variables'
condition: succeededOrFailed()
Centralized CI configuration
To centrally manage supported CI evaluation settings for Azure DevOps pipelines through the Lifecycle organization and application hierarchy, see the CI Configuration REST API.
Search results
No results found