From 04b057a20bcc349e0f44b87dc08000d6858f8670 Mon Sep 17 00:00:00 2001 From: Isuru Date: Tue, 30 Apr 2024 15:06:38 +0530 Subject: [PATCH 01/10] Add Jfrog scan template --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index 91938bf..1855837 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -45,3 +45,11 @@ jobs: parameters: API_KEY: $(FOSSA-API-KEY) BRANCH: master + - template: + parameters: + ACCESS_TOKEN: + PROJECT_TYPE: mvn + INSECURE_TLS: true + GITHUB_CONNECTION: + CONNECTION_NAME: + URL: \ No newline at end of file From 0b77fd0d2c37a033dbcb437309bffaad98c17079 Mon Sep 17 00:00:00 2001 From: CharinduThisara Date: Tue, 30 Apr 2024 15:13:00 +0530 Subject: [PATCH 02/10] Update SCA scan template with JFrog parameters --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index 1855837..b72cf3e 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -45,11 +45,10 @@ jobs: parameters: API_KEY: $(FOSSA-API-KEY) BRANCH: master - - template: + - template: ci-pipelines/templates/sca-scan-jfrog.yaml@templates parameters: - ACCESS_TOKEN: PROJECT_TYPE: mvn - INSECURE_TLS: true - GITHUB_CONNECTION: - CONNECTION_NAME: - URL: \ No newline at end of file + GITHUB_CONNECTION: $(GITHUB_CONNECTION) # GitHub connection name to Show the vulnerability report as a PR comment + ACCESS_TOKEN: $(ACCESS_TOKEN) # JFrog access token + CONNECTION_NAME: $(CONNECTION_NAME) # JFrog SERVER ID + URL: $(URL) # JFrog platform URL. \ No newline at end of file From b44046282d093a70b01ab0ec7b2770c08b089bb1 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:18:29 +0530 Subject: [PATCH 03/10] Update parameter names --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index b72cf3e..8ca6e18 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -27,7 +27,7 @@ pr: variables: - group: asgardeo-common-secrets -pool: 'asgardeo-shared-scale-set-agents' +pool: "asgardeo-shared-scale-set-agents" resources: repositories: @@ -50,5 +50,5 @@ jobs: PROJECT_TYPE: mvn GITHUB_CONNECTION: $(GITHUB_CONNECTION) # GitHub connection name to Show the vulnerability report as a PR comment ACCESS_TOKEN: $(ACCESS_TOKEN) # JFrog access token - CONNECTION_NAME: $(CONNECTION_NAME) # JFrog SERVER ID - URL: $(URL) # JFrog platform URL. \ No newline at end of file + SERVER_ID: $(CONNECTION_NAME) # JFrog SERVER ID + SERVER_URL: $(URL) # JFrog platform URL. From e9e28097b3f765e0bb3d274f87ff4af8f6ff4933 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:21:03 +0530 Subject: [PATCH 04/10] Fix autoformatting error --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index 8ca6e18..3843e92 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -27,7 +27,7 @@ pr: variables: - group: asgardeo-common-secrets -pool: "asgardeo-shared-scale-set-agents" +pool: 'asgardeo-shared-scale-set-agents' resources: repositories: From 5ae17ae0c320374021033a27535094eaa2986598 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:35:25 +0530 Subject: [PATCH 05/10] Update template release version --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index 3843e92..d0ccfd6 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -34,7 +34,7 @@ resources: - repository: templates type: github name: wso2-enterprise/azure-pipeline-templates - ref: refs/tags/v1.2.11 + ref: refs/tags/v1.4.1 endpoint: asgardeo-github-sca-scan jobs: From 8b4a23d611b53927fcd8025dc07582f343997bd3 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:45:35 +0530 Subject: [PATCH 06/10] Hardcode github connection, remove SERVER_ID and SERVER_URL parameters --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index d0ccfd6..e389a16 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -48,7 +48,5 @@ jobs: - template: ci-pipelines/templates/sca-scan-jfrog.yaml@templates parameters: PROJECT_TYPE: mvn - GITHUB_CONNECTION: $(GITHUB_CONNECTION) # GitHub connection name to Show the vulnerability report as a PR comment + GITHUB_CONNECTION: asgardeo-github-sca-scan ACCESS_TOKEN: $(ACCESS_TOKEN) # JFrog access token - SERVER_ID: $(CONNECTION_NAME) # JFrog SERVER ID - SERVER_URL: $(URL) # JFrog platform URL. From 236bec1c600831006c8e36ded6ea39226e2e004a Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:50:42 +0530 Subject: [PATCH 07/10] Update template release version --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index e389a16..ae2ae19 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -34,7 +34,7 @@ resources: - repository: templates type: github name: wso2-enterprise/azure-pipeline-templates - ref: refs/tags/v1.4.1 + ref: refs/tags/v1.4.2 endpoint: asgardeo-github-sca-scan jobs: From bf09d6efb8040faadabfbb1aa3bf53ec078ccc16 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 14:57:56 +0530 Subject: [PATCH 08/10] Change access token variable name --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index ae2ae19..497efa6 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -49,4 +49,4 @@ jobs: parameters: PROJECT_TYPE: mvn GITHUB_CONNECTION: asgardeo-github-sca-scan - ACCESS_TOKEN: $(ACCESS_TOKEN) # JFrog access token + ACCESS_TOKEN: $(JFROG-ACCESS-TOKEN) # JFrog access token From df7db7587c3f8f6228de354d2991326d4157d9c3 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 15:19:27 +0530 Subject: [PATCH 09/10] Move Jfrog test to run first --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index 497efa6..eebd539 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -41,12 +41,12 @@ jobs: - job: sca_scan displayName: SCA scan steps: - - template: ci-pipelines/templates/sca-scan.yaml@templates - parameters: - API_KEY: $(FOSSA-API-KEY) - BRANCH: master - template: ci-pipelines/templates/sca-scan-jfrog.yaml@templates parameters: PROJECT_TYPE: mvn GITHUB_CONNECTION: asgardeo-github-sca-scan ACCESS_TOKEN: $(JFROG-ACCESS-TOKEN) # JFrog access token + - template: ci-pipelines/templates/sca-scan.yaml@templates + parameters: + API_KEY: $(FOSSA-API-KEY) + BRANCH: master From 9c46856c3f374c8213f040c914542f0630b25173 Mon Sep 17 00:00:00 2001 From: Isuru Date: Thu, 2 May 2024 15:39:06 +0530 Subject: [PATCH 10/10] Update template release version --- .azure/asgardeo-java-oidc-sdk-sca-scan.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml index eebd539..e313155 100644 --- a/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml +++ b/.azure/asgardeo-java-oidc-sdk-sca-scan.yaml @@ -34,7 +34,7 @@ resources: - repository: templates type: github name: wso2-enterprise/azure-pipeline-templates - ref: refs/tags/v1.4.2 + ref: refs/tags/v1.4.3 endpoint: asgardeo-github-sca-scan jobs: