Answer – B
The right tool for this is SonarQube. Below is what the documentation on Azure DevOps mentions about the tool-
Option A is incorrect since this is used for finding and fixing open source vulnerabilities.
Option C is incorrect since this is used as a CI/CD tool.
Option D is incorrect since this is used to check for errors in Java-based applications.
For more information on implementing SonarQube, please visit the below URL-
https://www.azuredevopslabs.com/labs/vstsextend/sonarqube/