Azure Pipelines

Install the Marketplace task, add ScrutoraScan@1 to your pipeline, and findings render on a build tab via SARIF. Offline, no API key, and your code never leaves the agent.

01 · Setup

4 steps.

01Install the extension

Add the Scrutora Scan extension to your Azure DevOps organization from the Visual Studio Marketplace.

02Add the task

Reference the task in your pipeline YAML with your frameworks and gating severity.

- task: ScrutoraScan@1
  inputs:
    frameworks: dpdpa,hipaa
    failOn: high          # none|low|medium|high|critical
03View findings on a build tab

The task publishes SARIF as the CodeAnalysisLogs artifact. Install Microsoft's free SARIF SAST Scans Tab extension to render findings on a build tab automatically.

04Optional: keep the results in Scrutora

By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.

docker run --rm -v "$PWD:/src" -w /src \
  -e SCRUTORA_API_KEY \
  ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
  scan . --no-ai \
    --frameworks dpdpa,hipaa \
    --json-output scrutora.json \
    --output scrutora-report.pdf \
    --upload

# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.

# ── GitHub Actions: use the action's own inputs instead ─────────────────────
#   - id: scan
#     uses: scrutora/scrutora-scan@v1
#     with:
#       upload: true
#       api-key: ${{ secrets.SCRUTORA_API_KEY }}
#   - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"
02 · What you get

After the first run.

Build gating

failOn fails the build on high/critical findings so non-compliant code can't ship.

SARIF scans tab

Findings render on a build tab via the CodeAnalysisLogs artifact.

Obligation citations

Each finding maps to the exact DPDPA/HIPAA/PCI obligation, not a generic rule id.

Runs on hosted agents

Works on Microsoft-hosted ubuntu agents (Docker included) or any self-hosted agent with Docker.

03 · Questions

The ones people actually ask.

Where do the results appear?

As the CodeAnalysisLogs build artifact (SARIF v2.1.0). With the free SARIF SAST Scans Tab extension they render on a dedicated build tab.

Does it run on self-hosted agents?

Yes, as long as the agent has Docker. Microsoft-hosted ubuntu agents include it by default.

Which frameworks are supported?

DPDPA, HIPAA, GDPR, PCI-DSS, RBI and more, set the frameworks input.

Azure Marketplace