Azure DevOps
Overview
The Azure DevOps connector links your Azure DevOps organization to Nullify so that source-control activity drives security scanning, pull request reviews, and two-way ticket status sync — without developers leaving their existing workflow.
Nullify authenticates to Azure DevOps with the OAuth client-credentials flow (Client ID, Client Secret, and Tenant ID), then subscribes to Azure DevOps service hooks that deliver Git and work-item events to Nullify over an authenticated webhook.
This page describes what the integration provides. For the step-by-step setup — registering the Azure app, granting permissions, and creating the webhooks — see the Azure DevOps Install guide.
What you get
Pull request reviews
When a pull request is created or updated in a connected repository, Nullify reviews the changed code and posts its findings back as a PR review. Replies to Nullify's PR comments are also handled: when a developer comments on a Nullify review thread, the connector picks up the reply and continues the conversation in-thread.
Pull request gating and review behaviour are configured in the dashboard under Configure → Pull Requests (or via the admin API), including whether the "Nullify" check can fail the build on net-new findings at or above your chosen priority threshold.
Nullify does not open autofix pull requests on Azure DevOps — autofix PR creation is currently available on other Git platforms. The Azure connector covers PR reviews, push scanning, and ticket sync.
Push scanning
Every push to a connected repository is delivered to Nullify. The connector emits a scan event for each updated branch (tag pushes and branch deletions are ignored), and pushes to the repository's default branch additionally trigger the default-branch pipeline so your baseline security posture stays current.
Work-item (ticketing) status sync
When Nullify files a finding as an Azure DevOps work item, work-item updated events flow back to Nullify. A state change on a tracked work item (for example moving it to Resolved, Closed, or Done) is synced to the matching Nullify finding ticket, keeping the finding's status aligned with what your team does in Azure Boards. Nullify maps Azure's out-of-the-box state vocabulary by default and honours a per-tenant status map for teams running a custom Azure Boards process.
Events the connector subscribes to
Nullify creates Azure DevOps service-hook subscriptions for the following events on each connected repository:
Code pushed
git.push
Push scanning (all branches + default branch)
Pull request created
git.pullrequest.created
PR reviews
Pull request updated
git.pullrequest.updated
PR reviews
Pull request commented
ms.vss-code.git-pullrequest-comment-event
PR review replies
Work item updated
workitem.updated
Ticket status sync
Webhook deliveries are authenticated: each subscription carries an HTTP Basic credential (username nullify plus a per-install shared secret), and Nullify rejects deliveries that don't match.
Setup
Subscriptions can be created for you from the Nullify dashboard across the whole organization or per repository, or configured manually in Azure DevOps. The full walkthrough lives in the Azure DevOps Install guide.
Last updated