From fed0ef0a2011e0cf65afdc94ac2b3eda4d82050c Mon Sep 17 00:00:00 2001 From: Travis Plunk Date: Tue, 5 Feb 2019 15:58:43 -0800 Subject: [PATCH] Add binskim to coordinated build and increase timout (#8834) Add binskim to coordinated build and increase timout ## PR Context Total timeout for the old build was 220 minutes. The portions before the compliance take ~30 minutes. So, I went with 180. I also found I missed binskim when doing this work --- .../azureDevOps/templates/compliance.yml | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/tools/releaseBuild/azureDevOps/templates/compliance.yml b/tools/releaseBuild/azureDevOps/templates/compliance.yml index f0d331423e..c333b6de75 100644 --- a/tools/releaseBuild/azureDevOps/templates/compliance.yml +++ b/tools/releaseBuild/azureDevOps/templates/compliance.yml @@ -8,8 +8,9 @@ jobs: ${{ parameters.parentJobs }} pool: name: Package ES CodeHub Lab E - # APIScan can take a long time - timeoutInMinutes: 90 + + # APIScan can take a long time + timeoutInMinutes: 180 steps: - template: SetVersionVariables.yml @@ -53,6 +54,17 @@ jobs: debugMode: false continueOnError: true + - task: securedevelopmentteam.vss-secure-development-tools.build-task-binskim.BinSkim@3 + displayName: 'Run BinSkim ' + inputs: + InputType: Basic + AnalyzeTarget: '$(CompliancePath)\*.dll;$(CompliancePath)\*.exe' + AnalyzeSymPath: 'SRV*' + AnalyzeVerbose: true + AnalyzeHashes: true + AnalyzeStatistics: true + continueOnError: true + - task: securedevelopmentteam.vss-secure-development-tools.build-task-policheck.PoliCheck@1 displayName: 'Run PoliCheck' inputs: