这件事从昨天开始就发生了。
在过去的几个月中,我将Whitesource Bolt scan(流行的 Snyk 的免费替代品)集成到我们的 DevOps 项目中。
扫描我们的包裹通常需要几分钟的时间,我们对管道感到满意。
这是管道中的典型编辑日志
Starting: WhiteSource Bolt Scan
==============================================================================
Task : WhiteSource Bolt
Description : Detect security vulnerabilities, problematic open source licenses.
Version : 21.3.2
Author : WhiteSource
Help : http://www.whitesourcesoftware.com
==============================================================================
Working directory is /home/vsts/work/1/s
Getting scan config data
unifiedAgent.config file created successfully at /home/vsts/work/1/s
Finished getScanConfigData
Finished archive and encryption
Starting Upload zip file to s3
Getting temp credentials
Finished to prepare scm scan request
Sending SCM scan request …
Run Code Online (Sandbox Code Playgroud) dependency-management azure-devops azure-pipelines whitesource-bolt