Skip to content

ci: add SonarQube static analysis and quality gate - #728

Draft
defangdevs wants to merge 1 commit into
masterfrom
feat/sonarqube-ci
Draft

defangdevs wants to merge 1 commit into
masterfrom
feat/sonarqube-ci

Conversation

@defangdevs

@defangdevs defangdevs commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Adds SonarQube static analysis for pushes to master and same-repository pull requests. The dedicated workflow uses the official scanner pinned to v8.2.2, fetches full history, and fails when analysis or the quality gate fails. It supports SonarQube Cloud by default and an existing Server through repository variables.

Maintained source and tests are classified separately; generated module/ARM files, vendored assets, and rendered snapshots are excluded. An explicit Python language pattern includes the extensionless bin/agentbox CLI. Fork and Dependabot runs skip the secret-bearing job; the workflow uses read-only repository permissions and does not persist checkout credentials.

Validation:

  • PASS: full native suite, nix build -L --keep-going --max-jobs 4 --cores 1 --no-link .#ci-native (aarch64-linux).
  • PASS: pinned workflow lint and whitespace validation.
  • PASS: six configuration-preflight cases covering Cloud, Server, missing token/key, and missing Cloud organization.
  • PASS: manual correctness and credential-handling review.
  • BLOCKED: first GitHub analysis run reached the configuration preflight and confirmed SONAR_TOKEN, SONAR_PROJECT_KEY, and SONAR_ORGANIZATION are empty. Authenticated analysis and the baseline quality-gate result remain unverified.

Activation requires a SonarQube project, repository secret SONAR_TOKEN, variable SONAR_PROJECT_KEY, and (for Cloud) SONAR_ORGANIZATION. SONAR_HOST_URL defaults to https://sonarcloud.io. This session's GitHub credential receives HTTP 403 for Actions secrets/variables, so it cannot verify or configure them. Cloud Automatic Analysis must be disabled for CI-based analysis. Establish a master baseline before PR analysis; the Server edition/Cloud plan must support PR analysis. No coverage reports are generated by this change.

Setup and scan scope are documented in the Development wiki. Branch protection and the existing Validate module & VM gate are unchanged. Keep this PR in draft until the project configuration and an authenticated scan are verified.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant