Set up the Azure DevOps integration
Follow these steps to set up Fluid Attacks' integration with Azure DevOps:
- Go to your Azure DevOps Organization Settings and ensure it allows third-party application access via OAuth.
- Azure allows you to configure certain issue templates with custom fields, some being mandatory. Since the integration is generic, you need to access your project, go to Project Settings and, in Permissions, ensure you have the option Bypass rules on work item updates set to Allow for the integration to function correctly.
Note: To avoid creating duplicate issues, the integration first checks if there is an existing issue with the same title as the type of vulnerability. If it finds a match, it will use it as the parent issue and create only the associated "Tasks" for each individual vulnerability of the type in question.
-
On Fluid Attacks' platform, access the Integrations section from the collapsible sidebar.
-
Click
Use integration in the
Azure DevOps card. If your organization has set up this integration before, the card does not show that button, and you have to click the available gear icon (
) instead.
-
Click the Connect button corresponding to the group for which you desire the integration.
If instead you wish to modify details (e.g., organization, project, creating issues automatically for reported vulnerabilities) of an existing connection, you can click on the Edit button available next to the group name, make the necessary changes and click Update to finish setting up the integration.
-
Click on Authorize to connect your group to the Azure DevOps account.
-
Read the permissions you give Fluid Attacks with this integration and click the Accept button to agree to them.
-
Once redirected to the platform, enter your Azure DevOps organization and project names.
Note: Issues are created for vulnerabilities reported after setting up the integration with this feature enabled and not for those reported before.
- Click the Update button and you will be all set.
To see the automatically created issues on Azure DevOps, access you project and select Boards and then Work items from the left-side menu.
Inside the issue, you can see the
Location and Specific details of reported vulnerabilities of the type in question, among other relevant information.
On Fluid Attacks' platform, to show you where you are using this integration across your groups, the Azure DevOps card displays how many of the groups you have access to have the integration configured.
Free trial