Version 3.0.0 

The Synopsys Detect for Azure DevOps plugin, formerly known as Black Duck Detect plugin for TFS/VSTS, is architected to seamlessly integrate Synopsys Detect with Azure DevOps build and release pipelines. Synopsys Detect makes it easier to set up and scan code bases using a variety of languages and package managers.

The Synopsys Detect plugin for Azure DevOps supports native scanning in your Azure DevOps environment to run Software Composition Analysis (SCA) on your code.

As a Synopsys and Azure DevOps user, Synopsys Detect Extension for Azure DevOps enables you to:

Using the Synopsys Detect Extension for Azure DevOps together with Black Duck enables you to use Azure DevOps to automatically create Black Duck projects from your Azure DevOps projects.

Invoking Synopsys Detect

Synopsys recommends invoking Synopsys Detect from the CI (build) pipeline.  Scanning during CI enables Synopsys Detect to break your application build, which is effective for enforcing policies like preventing the use of disallowed or vulnerable components.


Basic workflow


Using Synopsy Detect to analyze your code in Azure involves the following basic steps:

  1. Make sure you satisfy system and other requirements
  2. Download and configure the Synopsys Detect extension in Azure
  3. Configure build agent and pipeline
  4. Configure Black Duck connection
  5. Configure Synopsys Detect arguments
  6. Run pipeline and invoke scan
  7. Examine the analysis results