# Sonatype for Azure DevOps

The Sonatype for Azure DevOps extension integrates with the Azure DevOps pipeline to run policy evaluations in the build workspace. It adds a new step within the build, during which Sonatype IQ Server scans applications to identify any open-source security, license, or quality policy violations. It can be configured to fail the build or generate a warning. This allows the build maintainers to understand the reasons for build failures and plan a remediation strategy.

This extension wraps the [Sonatype IQ CLI](https://help.sonatype.com/en/sonatype-iq-cli.html "Sonatype IQ CLI").

The Sonatype for Azure DevOps extension is available on the [Visual Studio Marketplace](https://marketplace.visualstudio.com/items?itemName=SonatypeIntegrations.nexus-iq-azure-extension).

## Main Features

- Perform a Sonatype IQ Server policy evaluation on files in the build workspace.
- Display scan results within Azure DevOps pipeline report.
- Provide a link to a comprehensive Sonatype Lifecycle policy evaluation report indicating violation details and remediation recommendations.

## [Release Notes](https://help.sonatype.com/en/sonatype-for-azure-devops.html#release-notes-326934_body)

iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.

# [iq-azure-devops](https://sonatype.github.io/iq-azure-devops/)

# Changelog

## Version 2.13.1 (July 08, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-2131-july-08-2026)
- Fixed a regression that caused all policy evaluations to fail with “Cannot read properties of undefined (reading ‘retrieveSecret’)

## Version 2.13.0 (July 08, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-2130-july-08-2026)
- Introduced granular exit codes
- Enhanced results cleanup to prevent stale information from displaying in the UI
- Improved support for HTTP proxy configuration in pipeline tasks

## Version 2.12.0 (June 05, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-2120-june-05-2026)
- Added support for .NET reachability analysis
- Added support for reachability analysis evidence

## Version 2.11.0 (May 07, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-2110-may-07-2026)
- Updated the IQ CLI to be dynamically downloaded at runtime instead of being bundled within the extension
- Fixed an issue where proprietary component regex patterns were not being processed correctly

## Version 2.10.0 (April 10, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-2100-april-10-2026)
- Added support for API-based CI configuration
- Added support for Sonatype Container Scanner

## Version 2.9.2 (March 06, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-292-march-06-2026)
- Maintenance release

## Version 2.9.1 (February 10, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-291-february-10-2026)
- Maintenance release

## Version 2.9.0 (February 10, 2026) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-290-february-10-2026)
- Added support for JavaScript reachability analysis
- Implemented security controls for the “IQ CLI Download URL” parameter in the Sonatype Evaluate task
- Added basic authentication support for “IQ CLI Download URL” parameter
- Sonatype IQ build tabs are no longer visible when pipeline doesn’t contain any Sonatype tasks

## Version 2.8.2 (December 17, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-282-december-17-2025)
- Maintenance release

## Version 2.8.1 (December 05, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-281-december-05-2025)
- Fixed an edge case where scans failed for npm projects

## Version 2.8.0 (November 07, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-280-november-07-2025)
- Added support for npm workspaces
- Improved scan performance for pnpm-lock.yaml files

## Version 2.7.0 (October 09, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-270-october-09-2025)
- Added support for Docker Client v28 in Docker Image Analysis
- Added support for scanning pnpm-lock.yaml v9 manifest files

## Version 2.6.3 (September 12, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-263-september-12-2025)
- Added support for analyzing Java 25 bytecode

## Version 2.6.2 (August 15, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-262-august-15-2025)
- Maintenance release

## Version 2.6.1 (August 15, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-261-august-15-2025)
- Added support for analyzing Java 23 and Java 24 bytecode

## Version 2.6.0 (July 11, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-260-july-11-2025)
- Added SARIF file generation capability
- Added new Reachability Analysis tab

## Version 2.5.0 (June 12, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-250-june-12-2025)
- Added support for SBOM generation
- Added support for publishing evaluation results as a pipeline artifact
- Added support to view multiple application-evaluation summaries in the ‘Sonatype IQ Summary Report’ tab
- Added support for IQ Server self-signed certificates
- Fixed issue with broken ‘Developer Priorities’ report link

## Version 2.4.3 (May 12, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-243-may-12-2025)
- Improved pipeline status visibility in the extension tabs

## Version 2.4.2 (April 29, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-242-april-29-2025)
- Fixed a Reachability Analysis compatibility issue with previous IQ Server versions

## Version 2.4.1 (April 24, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-241-april-24-2025)
- Fixed a webpack bundler issue affecting the `SonatypeEvaluate` task

## Version 2.4.0 (April 22, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-240-april-22-2025)
- Added `SonatypeEvaluate` task to run policy evaluations using any version of the Sonatype IQ CLI
- Fixed an issue affecting `ignoreScanningError` and `ignoreSystemError` parameters
- Added new reachability parameters (`enableReachability` and `reachabilityNamespaces`) to replace the previous options (`enableCallflow` and `callflowNamespaces`)

## Version 2.3.2 (April 03, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-232-april-03-2025)
- Updated the ‘ignoreScanningError’ input to allow scans to continue even if some files can’t be accessed

## Version 2.3.1 (March 11, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-231-march-11-2025)
- Fixed Node 20 runtime not being utilized as intended in pipelines
- Fixed handling of IQ Server connectivity when a trailing slash existed in the URL

## Version 2.3.0 (March 06, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-230-march-06-2025)
- Added Priorities URL to the scan result
- Added Priorities URL to the widget views

## Version 2.2.0 (February 18, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-220-february-18-2025)
- Added support for reachability analysis in Java (or any JVM language) binaries found in the scan targets to identify method signatures that trigger security vulnerabilities
- Fixed an issue that prevented components from being identified when scanning a `pom.xml` with missing nested component values
- Updated the extension’s name, logos, and documentation to improve the look and feel

## Version 2.1.0 (February 05, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-210-february-05-2025)
- Added branch name collection when a scan runs in a Git repository context

## Version 2.0.6 (January 09, 2025) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-206-january-09-2025)
- Updated the pipeline task to be compatible with Node 20, resolving issues with Azure DevOps agents

## Version 2.0.5 (December 10, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-205-december-10-2024)
- Maintenance release

## Version 2.0.4 (November 08, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-204-november-08-2024)
- Maintenance release

## Version 2.0.3 (October 11, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-203-october-11-2024)
- Maintenance release

## Version 2.0.2 (September 04, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-202-september-04-2024)
- Maintenance release

## Version 2.0.1 (August 20, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-201-august-20-2024)
- Maintenance release

## Version 2.0.0 (August 13, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-200-august-13-2024)
- Java 17 is now required to execute the `NexusIqPipelineTask`

## Version 1.7.21 (August 12, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1721-august-12-2024)
- Updated internal dependencies so Java 17 is not required to run the plugin

## Version 1.7.20 (August 08, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1720-august-08-2024)
- Maintenance release

## Version 1.7.19 (July 11, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1719-july-11-2024)
- Maintenance release

## Version 1.7.18 (June 26, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1718-june-26-2024)
- Maintenance release

## Version 1.7.17 (June 4, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1717-june-4-2024)
- Maintenance release

## Version 1.7.16 (May 15, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1716-may-15-2024)
- Maintenance release

## Version 1.7.15 (April 25, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1715-april-25-2024)
- Made NexusIqPipelineTask work on agents running on Node 16

## Version 1.7.14 (April 9, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1714-april-9-2024)
- Maintenance release

## Version 1.7.13 (March 6, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1713-march-6-2024)
- Maintenance release

## Version 1.7.12 (February 7, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1712-february-7-2024)
- Maintenance release

## Version 1.7.11 (January 22, 2024) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1711-january-22-2024)
- Maintenance release

## Version 1.7.10 (December 11, 2023) [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1710-december-11-2023)
- Maintenance release

## Version 1.7.9 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-179)
- Maintenance release

## Version 1.7.8 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-178)
- Maintenance release

## Version 1.7.7 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-177)
- Naming updates for legacy violations

## Version 1.7.6 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-176)
- Maintenance release

## Version 1.7.5 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-175)
- Maintenance release

## Version 1.7.4 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-174)
- Optionally use the $(Pipeline.Workspace) folder as a base for scanning

## Version 1.7.3 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-173)
- Maintenance release

## Version 1.7.2 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-172)
- Maintenance release

## Version 1.7.1 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-171)
- Maintenance release

## Version 1.7.0 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-170)
- Maintenance release

## Version 1.6.9 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-169)
- Maintenance release

## Version 1.6.8 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-168)
- Maintenance release

## Version 1.6.7 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-167)
- Maintenance release

## Version 1.6.6 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-166)
- Maintenance release

## Version 1.6.5 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-165)
- Maintenance release

## Version 1.6.4 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-164)
- Maintenance release

## Version 1.6.3 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-163)
- Maintenance release

## Version 1.6.2 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-162)
- Maintenance release

## Version 1.6.1 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-161)
- Maintenance release

## Version 1.5.7 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-157)
- Maintenance release

## Version 1.5.6 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-156)
- Maintenance release

## Version 1.5.5 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-155)
- Maintenance release

## Version 1.5.4 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-154)
- Fixed Nexus IQ Build Report to properly show the icon for “notify” actions

## Version 1.5.2 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-152)
- Maintenance release

## Version 1.5.0 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-150)
- Added the organization ID parameter, used for automatic IQ apps

## Version 1.4.0 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-140)
- Added a task option to enable debug logging for IQ Policy Evaluations
- Improved the summary message for policy evaluations
- Added a new **Nexus IQ Summary Report** tab on Build view

## Version 1.3.35 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1335)
- Maintenance release

## Version 1.3.34 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1334)
- Maintenance release

## Version 1.3.33 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1333)
- Maintenance release

## Version 1.3.32 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1332)
- Maintenance release

## Version 1.3.31 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1331)
- Maintenance release

## Version 1.3.30 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1330)
- Maintenance release

## Version 1.3.28 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1328)
- Maintenance release

## Version 1.3.27 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1327)
- Maintenance release

## Version 1.3.26 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1326)
- Maintenance release

## Version 1.3.25 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1325)
- Maintenance release

## Version 1.3.24 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1324)
- Maintenance release

## Version 1.3.23 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1323)
- Maintenance release

## Version 1.3.22 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1322)
- Maintenance release

## Version 1.3.19 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1319)
- Maintenance release

## Version 1.3.18 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1318)
- Maintenance release

## Version 1.3.17 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1317)
- Maintenance release

## Version 1.3.16 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1316)
- Bug fix: Correctly show a long app id in dashboard widget

## Version 1.3.15 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1315)
- Maintenance release

## Version 1.3.14 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1314)
- Maintenance release

## Version 1.3.13 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1313)
- FIX: Correctly handle Multiple javaSystemProperties configuration

## Version 1.3.12 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1312)
- FIX: Corrected null ‘match’ error when handling javaSystemProperties configuration

## Version 1.3.11 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1311)
- Added support for handling Multiple javaSystemProperties configuration

## Version 1.3.10 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1310)
- Maintenance release

## Version 1.3.9 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-139)
- Maintenance release

## Version 1.3.8 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-138)
- Maintenance release

## Version 1.3.7 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-137)
- Maintenance release

## Version 1.3.6 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-136)
- Maintenance release

## Version 1.3.5 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-135)
- Maintenance release

## Version 1.3.4 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-134)
- Maintenance release

## Version 1.3.3 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-133)
- Bug fix: Correctly handle system errors such as IQ connection failures and mark the build as failed or unstable

## Version 1.3.2 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-132)
- Added support for http proxy configuration on Azure Pipeline Agents.

## Version 1.3.1 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-131)
- FIX: Reverted http proxy configuration support introduced in 1.3.0

## Version 1.3.0 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-130)
- Added support for http proxy configuration on Azure Pipeline Agents

## Version 1.2.15 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1215)
- Maintenance release

## Version 1.2.14 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1214)
- Maintenance release

## Version 1.2.13 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1213)
- Started sending component paths to the IQ Server, so they can be shown on Occurrences tab of reports.
- Accommodated expanded output of IQ CLI and larger numbers of artifacts

## Version 1.2.12 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1212)
- FIX: Reverted 1.2.11 release to alleviate a regression while scanning larger numbers of artifacts.

## Version 1.2.11 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1211)
- Started sending component paths to the IQ Server, so they can be shown on Occurrences tab of reports.

## Version 1.2.10 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-1210)
- Added the Artifact Staging Directory as another lookup location for scan artifacts, in addition to the Default Working Directory

## Version 1.2.9 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-129)
- Maintenance release

## Version 1.2.8 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-128)
- Provided a reminder on a pipeline to enable Nexus IQ for each project when it’s not already

## Version 1.2.7 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-127)
- Maintenance release

## Version 1.2.6 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-126)
- Maintenance release

## Version 1.2.5 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-125)
- Maintenance release

### Version 1.2.4 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-124)
- Maintenance release

## Version 1.2.3 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-123)
- Maintenance release

## Version 1.2.2 [Anchor](https://sonatype.github.io/iq-azure-devops/CHANGELOG#version-122)
- Maintenance release

## [Compatibility](https://help.sonatype.com/en/sonatype-for-azure-devops.html#compatibility-326934_body)

iq-azure-devops | Provide a Azure DevOps pipeline step which will run a policy evaluation against a set of files in the build workspace.

# [iq-azure-devops](https://sonatype.github.io/iq-azure-devops/)

# Compatibility

The organization ID parameter requires at least version 1.5.0 of the plugin and IQ Server 143 or higher

| Plugin Version | IQ Server Version | Azure DevOps Version | Java Runtime |
| --- | --- | --- | --- |
| 2.0.0 and newer | 180 and higher | Azure DevOps Services (hosted) | Java 17 |
|  |  | Azure DevOps Server 2019 |  |
| 1.2.0 to 1.7.21 | 66 and higher | Azure DevOps Services (hosted) | JDK 8, JDK 11 |
|  |  | Azure DevOps Server 2019 |  |
| 1.0.0 to 1.1.0 | 66 and higher | Azure DevOps Services (hosted) | JDK 8, JDK 11 |

## Installation and Configuration

Go to the [Installation and Configuration](https://help.sonatype.com/en/installation-and-configuration---sonatype-for-azure-devops.html "Installation and Configuration - Sonatype for Azure DevOps") page for steps to install and set up Sonatype IQ in your Azure DevOps pipelines.

## Evaluating Policies

The "SonatypeEvaluate" task appears in the jobs list during a build:

### Accessing/Viewing Results

Open **SonatypeEvaluate** to view a console output with the results of the evaluation:

The console output contains a summary of the policy evaluation and a link to the detailed report in IQ Server.

Select the **Sonatype IQ Summary Report** tab on the build to see a summary report of the policy evaluation for the scanned components:

|     |
| --- |
|  |

Select the **Sonatype IQ Build Report** tab on the build for a detailed report with all the components and their correspondent violations:

If reachability analysis is enabled, select the **Sonatype IQ Reachability Analysis** tab for a detailed report of components with vulnerable methods and which of those methods are actually reachable in your code. This tab also lets you navigate, at the component level, between the Reachability Analysis and Build Report tabs.

**Note**

`NexusIqPipelineTask` is still supported but has been deprecated and may be removed in a future version. The embedded IQ CLI has been removed from the extension package; the task now downloads the latest CLI automatically at runtime. If you need to pin a specific CLI version, use the `SonatypeEvaluate` task instead. See [Installation and Configuration](https://help.sonatype.com/en/installation-and-configuration---sonatype-for-azure-devops.html "Installation and Configuration - Sonatype for Azure DevOps") for details.

### SARIF File Generation

When the `sarifFile` input parameter is set, the `SonatypeEvaluate` task will emit a SARIF report named as you specify, containing all identified vulnerabilities. The path to the generated file is exposed via the task’s `sarifFile` output variable, which you can reference in downstream steps.

You can then publish that SARIF file as a pipeline artifact with the `PublishBuildArtifacts` task and view it in your build summary by installing the [SARIF SAST Scans Tab](https://marketplace.visualstudio.com/items?itemName=sariftools.scans) extension, which adds a _Scans_ tab to the build results UI.

Here’s an example pipeline snippet:

```
- task: SonatypeEvaluate@2 name: sonatypePolicyEvaluation inputs: nexusIqService: 'IQ-SERVICE-CONNECTION' applicationId: 'app-01' stage: 'Build' scanTargets: '**/target/*.jar' sarifFile: 'result.sarif'
task: PublishBuildArtifacts@1
inputs:
PathtoPublish: '$(sonatypePolicyEvaluation.sarifFile)'
ArtifactName: 'CodeAnalysisLogs'
publishLocation: 'Container'
condition: succeededOrFailed()
```

After your pipeline completes, open the _Scans_ tab on the build summary to review the vulnerabilities in the SARIF report.

## Add dashboard widgets for Sonatype IQ

For ease of use, the following widgets for Sonatype IQ can be added to the Azure DevOps dashboard.

1. Sonatype IQ Policy Evaluation widget: shows the policy evaluation results for the latest build.
2. Trends for Sonatype IQ Policy Evaluation: shows a historical trend of Sonatype IQ Policy evaluations of the last 5 builds.

**How to add Sonatype IQ widgets to the Azure DevOps Dashboard:**

1. Go to "Overview" → "Dashboards" and click the "Edit" button.

2. On the right-hand side, under "Add Widget", search for "Sonatype IQ":

3. Select the appropriate widget and click the "Add" button at the bottom right corner of the page. Click the "Done editing" button.

4. Sonatype IQ widget now displays the dashboard showing the results summary for the latest build and the historical summary for the last 5 builds.

|     |
| --- |
|  |

## Running Sonatype IQ in Azure Self-Hosted Agents

If you’re using an HTTP proxy within your infrastructure and Azure self-hosted build agents, you can specify the Azure DevOps agent’s proxy settings. These settings will then be automatically applied when connecting to IQ. For more information, refer to [Microsoft’s documentation](https://docs.microsoft.com/en-us/azure/devops/pipelines/agents/proxy?view=azure-devops&tabs=windows).

In the Azure-provided sample command:

```
./config.sh --proxyurl http://127.0.0.1:8888 --proxyusername "myuser" --proxypassword "mypass"
```

This would appear in the scan output as it is passed through to the IQ scan client:

```
...
-p
127.0.0.1:8888
-U
myuser:***
...
```

## Fetch SBOM Task Properties

Fetch SBOM is a task for retrieving an SBOM (Software Bill of Materials) file associated with a previous Lifecycle evaluation. It supports both the [CycloneDX](https://cyclonedx.org/) and [SPDX](https://spdx.dev/) standards. For configuration steps, see the [Installation and Configuration](https://help.sonatype.com/en/installation-and-configuration---sonatype-for-azure-devops.html "Installation and Configuration - Sonatype for Azure DevOps") page.

| Parameter | Required/Optional | Description |
| --- | --- | --- |
| `nexusIqService` | Required | Sonatype IQ service connection to use. |
| `applicationId` | Required | Must match the `applicationId` used in the preceding Evaluation task. |
| `scanId` | Required | Scan identifier produced by the Evaluation step. Pass it as `$(<evaluation-reference-name>.scanId)`. |
| `sbomStandard` | Required | SBOM standard: `spdx` or `cyclonedx`. |
| `sbomVersion` | Optional | Version of the SBOM standard. Available CycloneDX versions: `1.2`, `1.3`, `1.4`, `1.5`, `1.6`. Default version for CycloneDX is `1.6`. Available SPDX versions: `2.2`, `2.3`. Default version for SPDX is `2.3`. |
| `sbomFormat` | Optional | Output file format: `json` or `xml`. Default: `json`. |
| `acceptIqServerSelfSignedCertificates` | Optional | Accept self-signed TLS certificates from IQ Server. Default: `false`. |

**Note**

The reference name you assign to each task (e.g., `sonatypePolicyEvaluation`, `sonatypeFetchSbomTask`) becomes the prefix for its output variables. Adjust the variable references accordingly.

## Reachability Analysis

See [Reachability Analysis with Sonatype for Azure DevOps](https://help.sonatype.com/en/reachability-analysis-with-sonatype-for-azure-devops.html "Reachability Analysis with Sonatype for Azure DevOps") for how to enable Reachability in Java/JVM builds covering required permissions, the parameters, a usage example, and the default entry point strategy with tips on narrowing scope via namespaces.

## Git/jgit Configuration and Permissions

The Azure DevOps extension uses the Sonatype IQ CLI to perform scans.

During the scanning process, the CLI uses Git to detect the repository URL, commit hash, and branch name.

If native Git is available on the build agent, the CLI will use it; otherwise, it falls back to jgit (Java-based Git). When jgit is used, it attempts to create configuration files in the current user’s `$HOME` directory. If it doesn’t have permission to do so, you may see ERROR-level log messages—these are not critical to the scan and can be safely ignored. To avoid them, make sure native Git is installed on the build agent, or set the `XDG_CONFIG_HOME` environment variable to a directory that the build agent user can write to.

## Exit Codes

The pipelines emit the following exit codes:

| Exit Code | Description |
| --- | --- |
| 0 | Success |
| 1 | Policy violation |
| 2 | Scanning error |
| 3 | Reachability error |
| 4 | Configuration error |
| 5 | Connectivity error |
| 6 | Local I/O error |
| 7 | Authentication error |

The pipelines now emit the following output variables:

| Variable | Description |
| --- | --- |
| `CliExitCode` | Numeric exit code returned by the CLI. |
| `CliExitCategory` | Category name of the exit code. |
| `CliExitMessage` | Detailed error or success message. |

Usage example:

```
steps:
- task: SonatypeEvaluate@2
 name: iqEval
 displayName: 'Sonatype IQ policy evaluation'
 inputs:
 nexusIqService: 'nexus-iq-lifecycle'
 applicationId: 'an-application'
 scanTargets: pom.xml
 condition: succeededOrFailed()
- bash: |
 echo "CliExitCode: $(iqEval.CliExitCode)"
 echo "CliExitCategory: $(iqEval.CliExitCategory)"
 echo "CliExitMessage: $(iqEval.CliExitMessage)"
 displayName: 'Print Sonatype IQ task exit variables'
 condition: succeededOrFailed()
```

## Centralized CI configuration

To centrally manage supported CI evaluation settings for Azure DevOps pipelines through the Lifecycle organization and application hierarchy, see the [CI Configuration REST API](https://help.sonatype.com/en/ci-configuration-rest-api.html "CI Configuration REST API").

## Search results

No results found
