Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
ci: SonarQube-сканування (self-hosted) #3
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Uh oh!
There was an error while loading. Please reload this page.
ci: SonarQube-сканування (self-hosted) #3
Changes from all commits
b7a7dd8c1037a0File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Не вимагайте ручного секрету
SONAR_HOST_URL.За цілями PR автоматично налаштовуються
SONAR_HOST_URLіSONAR_PROJECT_KEY, а вручну додається лишеSONAR_TOKEN. Наразі репозиторій із одним токеном завжди отримуєpresent=falseі пропускає сканування. Передавайте URL через централізовану organization/repository variable або зафіксуйте адресу сервера у workflow.🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
always()запускає цей крок після помилки або скасування поточного scan. Оскільки наступні API-запити прив’язані лише до project key і номера PR, вони можуть отримати попередній завершений аналіз та опублікувати його як результат поточного commit.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P2: PR reruns can update the sticky comment with the previous analysis’s gate and issues. Poll the submitted Compute Engine task (or otherwise wait for this scan’s analysis) before fetching
project_statusand issues.Prompt for AI agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: vaulttec-dev/chrome-extension
Length of output: 400
🏁 Script executed:
Repository: vaulttec-dev/chrome-extension
Length of output: 4966
🏁 Script executed:
Repository: vaulttec-dev/chrome-extension
Length of output: 6013
🌐 Web query:
SonarQube API /api/qualitygates/project_status pullRequest analysisId semantics latest analysis report-task.txt ceTaskId💡 Result:
To programmatically check the Quality Gate status of a SonarQube analysis, you must interact with the asynchronous analysis process [1][2]. The report-task.txt file, generated in the scanner's working directory upon successful submission, provides the necessary entry point [3][4][5]. Process Overview: 1. Identify the ceTaskId: After the SonarScanner finishes submitting the report, a report-task.txt file is created containing the ceTaskId (Compute Engine Task ID) [3][1]. 2. Monitor Task Completion: Use the /api/ce/task endpoint with the ceTaskId to poll the status of the background analysis [1][2]. GET /api/ce/task?id= Continue polling until the task.status field returns "SUCCESS" [1][2]. 3. Retrieve analysisId: Once the status is "SUCCESS", the same /api/ce/task response will contain the analysisId (located in task.analysisId) [1][2]. 4. Get Quality Gate Status: Use the analysisId with the /api/qualitygates/project_status endpoint to get the final result [6][3][2]. GET /api/qualitygates/project_status?analysisId= Regarding /api/qualitygates/project_status and Pull Requests: While you can query this endpoint using projectKey and branch/pullRequest parameters (e.g., /api/qualitygates/project_status?projectKey=&pullRequest=), these requests may return inconsistent or summary-only data depending on your environment and authentication method [7][6]. For precise, reliable results—especially when automating CI/CD pipelines—it is considered best practice to use the analysisId obtained from the specific background task, as it ensures you are checking the status of the exact analysis just completed [6][1]. Top Results: [6][3][1][2]
Citations:
🌐 Web query:
SonarQube qualitygates/project_status pullRequest returns latest analysis or previous analysis while background task still running💡 Result:
When calling the SonarQube API endpoint api/qualitygates/project_status while a background task is still in progress, the API will return the status of the most recently completed analysis [1][2][3]. It does not automatically wait for or return the results of the pending analysis currently being processed by the compute engine [4][5]. Because the analysis is not fully incorporated into the project state until its corresponding background task completes (reaching a status of SUCCESS), any API call made before that completion will reflect the state from the previous, finished analysis [4][6][5]. To ensure you are retrieving the results of the specific, ongoing analysis, you should use one of the following methods: 1. Use sonar.qualitygate.wait=true: Adding this parameter to your scanner execution forces the analysis process to wait until the background task is fully processed by the SonarQube server before exiting [6][5]. This is generally the most robust approach for CI/CD pipelines [6]. 2. Poll the Background Task API: After the scanner finishes, you can use the ceTaskId (available in the report-task.txt file generated by the scanner) to poll the api/ce/task endpoint [7][2][8]. Once the task status is SUCCESS, you can then safely call api/qualitygates/project_status using the analysisId returned by the task status response [7][8]. 3. Monitor via Webhooks: Configure SonarQube webhooks to notify your system once a background task completes [9][10]. This avoids the need for polling altogether by pushing the result to you when it is ready [9]. Attempting to check the quality gate status immediately after the scanner finishes without waiting for the background task will frequently result in receiving "stale" or inaccurate data [1][3].
Citations:
Прив’яжіть PR-коментар до поточного Sonar task
Запит лише за
projectKeyіpullRequestможе показати попередній завершений аналіз, якщо поточний background task ще обробляється. ЗчитайтеceTaskIdзreport-task.txt, дочекайтесяSUCCESSдля цього task і берітьproject_statusзаanalysisId; без метаданих цього запуску коментар краще пропускати.🧰 Tools
🪛 Betterleaks (1.6.1)
[high] 119-119: Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.
(curl-auth-user)
🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Запит використовує застарілий параметр
components, тоді як актуальний контракт/api/issues/searchочікуєcomponentKeys. На сервері без сумісного alias запит завершиться помилкою, після чого гілкаexit 0пропустить PR-коментар і залишить workflow успішним без результатів аналізу.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P3: PR comments undercount findings once a PR has over 100 unresolved issues, while presenting the truncated count as total. Use the response
totaland paginate, or label the result as the first 100 findings.Prompt for AI agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ps=100завантажує лише першу сторінку, тоді як код використовує довжину отриманого масиву як загальну кількість. Для PR із понад 100 issues коментар покаже неправильний підсумок і повністю приховає решту результатів; потрібно обходити сторінки або брати загальну кількість ізpaging.total.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P2:
sonar.projectKeyis hardcoded here aschrome-extension, but the workflow also passes-Dsonar.projectKey=${{ env.SONAR_PROJECT_KEY }}(which defaults to the repo name or a variable). Having two sources of truth means local scans and CI could silently target different projects if either value drifts. Consider removing the hardcoded key from this file and relying solely on the CI-provided value (or vice versa).Prompt for AI agents
Uh oh!
There was an error while loading. Please reload this page.