For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure DevOps

Overview

The Azure DevOps connector links your Azure DevOps organization to Nullify so that source-control activity drives security scanning, pull request reviews, and two-way ticket status sync — without developers leaving their existing workflow.

Nullify authenticates to Azure DevOps with the OAuth client-credentials flow (Client ID, Client Secret, and Tenant ID), then subscribes to Azure DevOps service hooks that deliver Git and work-item events to Nullify over an authenticated webhook.

This page describes what the integration provides. For the step-by-step setup — registering the Azure app, granting permissions, and creating the webhooks — see the Azure DevOps Install guide.

What you get

Pull request reviews

When a pull request is created or updated in a connected repository, Nullify reviews the changed code and posts its findings back as a PR review. Replies to Nullify's PR comments are also handled: when a developer comments on a Nullify review thread, the connector picks up the reply and continues the conversation in-thread.

Pull request gating and review behaviour are configured in the dashboard under Configure → Pull Requests (or via the admin API), including whether the "Nullify" check can fail the build on net-new findings at or above your chosen priority threshold.

Nullify does not open autofix pull requests on Azure DevOps — autofix PR creation is currently available on other Git platforms. The Azure connector covers PR reviews, push scanning, and ticket sync.

Push scanning

Every push to a connected repository is delivered to Nullify. The connector emits a scan event for each updated branch (tag pushes and branch deletions are ignored), and pushes to the repository's default branch additionally trigger the default-branch pipeline so your baseline security posture stays current.

Work-item (ticketing) status sync

When Nullify files a finding as an Azure DevOps work item, work-item updated events flow back to Nullify. A state change on a tracked work item (for example moving it to Resolved, Closed, or Done) is synced to the matching Nullify finding ticket, keeping the finding's status aligned with what your team does in Azure Boards. Nullify maps Azure's out-of-the-box state vocabulary by default and honours a per-tenant status map for teams running a custom Azure Boards process.

Events the connector subscribes to

Nullify creates Azure DevOps service-hook subscriptions for the following events on each connected repository:

Event
Azure DevOps trigger
Used for

Code pushed

git.push

Push scanning (all branches + default branch)

Pull request created

git.pullrequest.created

PR reviews

Pull request updated

git.pullrequest.updated

PR reviews

Pull request commented

ms.vss-code.git-pullrequest-comment-event

PR review replies

Work item updated

workitem.updated

Ticket status sync

Webhook deliveries are authenticated: each subscription carries an HTTP Basic credential (username nullify plus a per-install shared secret), and Nullify rejects deliveries that don't match.

Setup

Subscriptions can be created for you from the Nullify dashboard across the whole organization or per repository, or configured manually in Azure DevOps. The full walkthrough lives in the Azure DevOps Install guide.

Last updated