# Azure DevOps - Nexus IQ Extension issue with scan Targets for Java Maven

**URL:** <https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913>\
**Category:** Sonatype Lifecycle & Firewall\
**Tags:** integrations, nexus-iq, azure\
**Created:** [April 15, 2020, 2:12pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913 "2020-04-15T14:12:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![azizbasha](https://avatars.discourse-cdn.com/v4/letter/a/f04885/32.png) [@azizbasha](https://community.sonatype.com/u/azizbasha)\
**Post date:** [April 15, 2020, 2:12pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/1 "2020-04-15T14:12:50Z")

</div>

Hi

I have created Java Maven pipeline using YAML.

Wherein i am using Nexus IQ Extension 1.2.1 for Nexus IQ Policy Evaluation

below is the Task in my pipeline -

_- task: SonatypeIntegrations.nexus-iq-azure-extension.nexus-iq-azure-pipeline-ask.NexusIqPipelineTask@1  
displayName: ‘Nexus IQ Policy Evaluation’  
inputs:  
nexusIqService: $(Serviceconnection.Nexus.IQ.Name)  
applicationId: $(appname\_nexus\_lc)  
scanTargets: '\*\*/_.jar, \*\*/_.war, \*\*/_.ear, \*\*/\*.tar.gz’

Nexus IQ is unable to scan targets in the Azure DevOps -\> Java Build Pipeline.

I have also tried with giving scan targets as below-

scanTargets : ‘$(Build.ArtifactsStagingDirectory)/\*\*/\*.war’’

Also with hard coded values scanTargets is unable to scan the Artifacts.

any ideas.

---

<div class="post-metadata">

**Author:** ![jyoung](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jyoung/32/89_2.png) [@jyoung](https://community.sonatype.com/u/jyoung)\
**Post date:** [May 11, 2020, 4:03pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/2 "2020-05-11T16:03:45Z")

</div>

I believe this is related, [Sign in to sonatype](https://ideas.sonatype.com/ideas/IDEAS-I-612), copying the response from there:

> The ability to scan the Artifacts Staging Directory is on the list of improvements we’d like to add to the Azure DevOps extension. The team rotates investment through our portfolio of integrations and there isn’t any planned work on Azure DevOps, however, when we circle back to it we will entertain how to fulfill this. Thanks for the idea.

---

<div class="post-metadata">

**Author:** ![pimbelien](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@pimbelien](https://community.sonatype.com/u/pimbelien)\
**Post date:** [June 17, 2020, 3:27pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/3 "2020-06-17T15:27:39Z")

</div>

Hi Justin  
I think Im facing the exact same problem. The task does not find anything from the Build.ArtifactStagingDirectory even though my .war is right there.  
Am I right to assume that basically right now the extention cannot scan from the Artifacts Staging Directory, but it would from some other directory?

---

<div class="post-metadata">

**Author:** ![jyoung](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jyoung/32/89_2.png) [@jyoung](https://community.sonatype.com/u/jyoung)\
**Post date:** [June 17, 2020, 5:09pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/4 "2020-06-17T17:09:09Z")

</div>

Correct, currently the scanning occurs within “Build.Repository.LocalPath” but not in “Build.ArtifactStagingDirectory”. We have a ticket in the backlog to fix but no timetable as to when we will be able to address this.

---

<div class="post-metadata">

**Author:** ![vipetrul](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/vipetrul/32/1410_2.png) [@vipetrul](https://community.sonatype.com/u/vipetrul)\
**Post date:** [August 7, 2020, 5:09pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/5 "2020-08-07T17:09:34Z")

</div>

In the meantime, as a workaround you could create a directory symlink from “Build.Repository.LocalPath” to “Build.ArtifactStagingDirectory”

---

<div class="post-metadata">

**Author:** ![mpuglin](https://avatars.discourse-cdn.com/v4/letter/m/5e9695/32.png) [@mpuglin](https://community.sonatype.com/u/mpuglin)\
**Post date:** [April 14, 2021, 1:59pm UTC](https://community.sonatype.com/t/azure-devops-nexus-iq-extension-issue-with-scan-targets-for-java-maven/3913/6 "2021-04-14T13:59:55Z")

</div>

This issue was addressed in release 1.2.10 of the Azure DevOps extension.

[Nexus IQ for Azure DevOps](https://marketplace.visualstudio.com/items?itemName=SonatypeIntegrations.nexus-iq-azure-extension)
