Azure Pipelines
Install the Marketplace task, add ScrutoraScan@1 to your pipeline, and findings render on a build tab via SARIF. Offline, no API key, and your code never leaves the agent.
4 steps.
Add the Scrutora Scan extension to your Azure DevOps organization from the Visual Studio Marketplace.
Reference the task in your pipeline YAML with your frameworks and gating severity.
- task: ScrutoraScan@1
inputs:
frameworks: dpdpa,hipaa
failOn: high # none|low|medium|high|criticalThe task publishes SARIF as the CodeAnalysisLogs artifact. Install Microsoft's free SARIF SAST Scans Tab extension to render findings on a build tab automatically.
By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.
docker run --rm -v "$PWD:/src" -w /src \
-e SCRUTORA_API_KEY \
ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
scan . --no-ai \
--frameworks dpdpa,hipaa \
--json-output scrutora.json \
--output scrutora-report.pdf \
--upload
# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.
# ── GitHub Actions: use the action's own inputs instead ─────────────────────
# - id: scan
# uses: scrutora/scrutora-scan@v1
# with:
# upload: true
# api-key: ${{ secrets.SCRUTORA_API_KEY }}
# - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"After the first run.
failOn fails the build on high/critical findings so non-compliant code can't ship.
Findings render on a build tab via the CodeAnalysisLogs artifact.
Each finding maps to the exact DPDPA/HIPAA/PCI obligation, not a generic rule id.
Works on Microsoft-hosted ubuntu agents (Docker included) or any self-hosted agent with Docker.