Skip to content

ci: add SonarQube Cloud static analysis and coverage tracking#52

Merged
wolpert merged 1 commit into
mainfrom
ci/sonarqube-cloud
Jun 11, 2026
Merged

ci: add SonarQube Cloud static analysis and coverage tracking#52
wolpert merged 1 commit into
mainfrom
ci/sonarqube-cloud

ci: add SonarQube Cloud static analysis and coverage tracking

4762bf6
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Jun 11, 2026 in 42s

Quality Gate failed

Failed conditions
1 Security Hotspot
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 64 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Define exact package version to avoid installing unverified releases.

See more on https://sonarcloud.io/project/issues?id=codeheadsystems_pk-auth&issues=AZ62_KFAXkfIv1lKlpHr&open=AZ62_KFAXkfIv1lKlpHr&pullRequest=52

Check warning on line 60 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" can lead to the execution of shell scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=codeheadsystems_pk-auth&issues=AZ62_KFAXkfIv1lKlpHp&open=AZ62_KFAXkfIv1lKlpHp&pullRequest=52

Check warning on line 64 in .github/workflows/ci.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" can lead to the execution of shell scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=codeheadsystems_pk-auth&issues=AZ62_KFAXkfIv1lKlpHq&open=AZ62_KFAXkfIv1lKlpHq&pullRequest=52

Check warning on line 0 in build.gradle.kts

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Dependency versions are not predictable if the lock file (gradle.lockfile or gradle/verification-metadata.xml) is missing.

See more on https://sonarcloud.io/project/issues?id=codeheadsystems_pk-auth&issues=AZ62_KG8XkfIv1lKlpHs&open=AZ62_KG8XkfIv1lKlpHs&pullRequest=52