0% found this document useful (0 votes)
5 views3 pages

Pubmind Core SonarQube Configuration

The document lists various SonarQube plugins and global server settings, including versions and functionalities for code quality and security across multiple programming languages. It also details project-specific scanner properties such as paths for binaries, coverage reports, and libraries used in the project. Additionally, it includes configurations for authentication and project metadata like name, key, and version.

Uploaded by

jonas231205
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views3 pages

Pubmind Core SonarQube Configuration

The document lists various SonarQube plugins and global server settings, including versions and functionalities for code quality and security across multiple programming languages. It also details project-specific scanner properties such as paths for binaries, coverage reports, and libraries used in the project. Additionally, it includes configurations for authentication and project metadata like name, key, and version.

Uploaded by

jonas231205
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

SonarQube plugins:

- Cobertura 2.0 (cobertura)


- PMD 3.3.1 (pmd)
- IaC Code Quality and Security 1.7.0.2012 (iac)
- PL/SQL Code Quality and Security 3.7.0.4372 (plsql)
- Scala Code Quality and Security 1.9.0.3429 (sonarscala)
- C# Code Quality and Security 8.36.1.44192 (csharp)
- Vulnerability Analysis 9.4.1.15913 (security)
- Java Code Quality and Security 7.11.0.29148 (java)
- HTML Code Quality and Security 3.6.0.3106 (web)
- Flex Code Quality and Security 2.7.0.2865 (flex)
- XML Code Quality and Security 2.5.0.3376 (xml)
- Text file Code Quality and Security [Link] (text)
- Checkstyle 9.2.1 (checkstyle)
- [Link] Code Quality and Security 8.36.1.44192 (vbnet)
- Swift Code Quality and Security 4.5.0.5305 (swift)
- YAML Analyzer 1.7.0 (yaml)
- Prometheus Exporter 1.0.0-SNAPSHOT (prometheusexporter)
- CFamily Code Quality and Security 6.32.0.44918 (cpp)
- Python Code Quality and Security 3.12.0.9583 (python)
- Code Smells 4.0.0 (smells)
- Go Code Quality and Security 1.9.0.3429 (go)
- JaCoCo 1.1.1.1157 (jacoco)
- Kotlin Code Quality and Security 2.9.0.1147 (kotlin)
- T-SQL Code Quality and Security 1.6.0.4844 (tsql)
- JavaScript/TypeScript/CSS Code Quality and Security 9.1.0.17747 (javascript)
- Ruby Code Quality and Security 1.9.0.3429 (ruby)
- Vulnerability Rules for C# 9.4.1.15913 (securitycsharpfrontend)
- Vulnerability Rules for Java 9.4.1.15913 (securityjavafrontend)
- License for SonarLint 9.4.0.54424 (license)
- Findbugs 4.0.5 (findbugs)
- Vulnerability Rules for JS 9.4.1.15913 (securityjsfrontend)
- Groovy 1.8 (groovy)
- Vulnerability Rules for Python 9.4.1.15913 (securitypythonfrontend)
- PHP Code Quality and Security 3.23.1.8766 (php)
- ABAP Code Quality and Security 3.10.0.3628 (abap)
- Configuration detection fot Code Quality and Security [Link] (config)
- Vulnerability Rules for PHP 9.4.1.15913 (securityphpfrontend)
Global server settings:
- [Link]=noreply@[Link]
- [Link]=false
- [Link]=false
- [Link]=false
- [Link]=[Link]
- [Link]=6CF5BE4F-AWRIk3VFrEe_XNA6vi10
- [Link]=[Link]
- [Link]=2022-05-04T00:19:37+0000
-
[Link]=build/reports/jacoco/test/[Link]
-
[Link]=master,develop,trunk,branch-.*,release-.
*
- [Link]=true
- [Link]=true
- [Link]=[Link]
clientlibs/clientlib-base/resources/images/logos/[Link]
- [Link]=116
- [Link]=200000
- [Link]=ACCEPTED
Project server settings:
Project scanner properties:
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/classes/
java/main
- [Link]=**/table/**/*.java, **/config/*.java,
**/entity/*.java, **/constant/*.java, **/consumer/*.java, **/controller/*.java,
**/dao/*.java, **/dao/*.java, **/events/*.java, **/kafka/*.java, **/monitor/*.java,
**/registry/*.java, **/repository/*.java, **/unused/*.java, **/util/*.java,
src/main/java/com/xxx/vod/catalog/[Link],
src/main/java/com/xxx/vod/catalog/[Link], **/beans/*.java,
**/assetlog/*.java, **/db/republisher/*.java, **/orphan/*.java,
**/builder/[Link], **/builder/[Link],
**/decorator/[Link], **/processor/[Link],
**/processor/[Link],
**/processor/[Link],
**/processor/[Link], **/processor/[Link],
**/processor/[Link]
- [Link]=/home/jenkins-aws/workspace/pubmind-
core_master/build/reports/jacoco/test/[Link]
- [Link]=[Link]
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/
jacoco/[Link]
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/
build/jacoco/[Link]
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/
classes/java/main
- [Link]=jacoco
- [Link]=/opt/java/openjdk
- [Link]=/home/gradle/.gradle/caches/modules-2/files-2.1/
[Link]/pubmind-schema/
0.0.242/713b9f81c225d6a6f58e8a737025d822999d31b3/[Link],/home/
gradle/.gradle/caches/modules-2/files-2.1/[Link]/lombok/1.16.20/
ac76d9b956045631d1561a09289cbf472e077c01/[Link],/home/gradle/.gradle/
caches/modules-2/files-2.1/[Link]/twsNextGenBaseInception/
1.0.72/8c18d06da195a86434eb094437adad9b409c725a/twsNextGenBaseInception-
[Link],/home/gradle/.gradle/caches/modules-2/files-2.1/
[Link]/inception-starter/
0.0.46/47fcf6b450ccb2edeaf4ba8d7419a94b8ec93175/[Link],/
home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/b-inception-
util/1.2.77/cabef44d0ef19358642b4e8b6628436ecfbe42b3/[Link],/
home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/svcutil/
1.0.177/3c268d8e6ae9cfce9929871bf108ab55610eb9b0/[Link],/home/
gradle/.gradle/caches/modules-2/fil...
- [Link]=11
- [Link]=11
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/
build/classes/java/test
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/
build/classes/java/main,/home/jenkins-aws/workspace/pubmind-core_master/build/
resources/main,/home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/
pubmind-schema/0.0.242/713b9f81c225d6a6f58e8a737025d822999d31b3/pubmind-schema-
[Link],/home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/
lombok/1.16.20/ac76d9b956045631d1561a09289cbf472e077c01/[Link],/home/
gradle/.gradle/caches/modules-2/files-2.1/[Link]/
twsNextGenBaseInception/1.0.72/8c18d06da195a86434eb094437adad9b409c725a/
[Link],/home/gradle/.gradle/caches/modules-2/files-
2.1/[Link]/inception-starter/
0.0.46/47fcf6b450ccb2edeaf4ba8d7419a94b8ec93175/[Link],/
home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/b-inception-
util/1.2.77/cabef44d0ef19358642b4e8b6628436ecfbe42b3/[Link],/
home/gradle/.gradle/caches/modules-2/files-2....
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/
test-results/test
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/
test-results/test
-
[Link]=/home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/
pubmind-schema/0.0.242/713b9f81c225d6a6f58e8a737025d822999d31b3/pubmind-schema-
[Link],/home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/
lombok/1.16.20/ac76d9b956045631d1561a09289cbf472e077c01/[Link],/home/
gradle/.gradle/caches/modules-2/files-2.1/[Link]/
twsNextGenBaseInception/1.0.72/8c18d06da195a86434eb094437adad9b409c725a/
[Link],/home/gradle/.gradle/caches/modules-2/files-
2.1/[Link]/inception-starter/
0.0.46/47fcf6b450ccb2edeaf4ba8d7419a94b8ec93175/[Link],/
home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/b-inception-
util/1.2.77/cabef44d0ef19358642b4e8b6628436ecfbe42b3/[Link],/
home/gradle/.gradle/caches/modules-2/files-2.1/[Link]/svcutil/
1.0.177/3c268d8e6ae9cfce9929871bf108ab55610eb9b0/[Link],/home/
gradle/.gradle/caches/modules-2/fil...
- [Link]=******
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master
- [Link]='Pubmind Core'
- [Link]=[Link]:pubmind-core
- [Link]=pubmind-core
- [Link]=unspecified
- [Link]=ScannerGradle
- [Link]=3.2-SNAPSHOT/Gradle 4.10.2
- [Link]=True
- [Link]=UTF-8
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/src/main
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/
build/test-results/test
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/src/test
- [Link]=/home/gradle
- [Link]=/home/jenkins-aws/workspace/pubmind-core_master/build/
sonar

Common questions

Powered by AI

SonarQube can analyze a range of vulnerabilities across different programming languages using several specialized plugins. For C#, Java, JavaScript (JS), and PHP, there are specific plugins like Vulnerability Rules for C# (securitycsharpfrontend), Java (securityjavafrontend), JS (securityjsfrontend), and PHP (securityphpfrontend) that target and identify vulnerabilities. These vulnerabilities are identified by analyzing code for security flaws such as SQL injection, cross-site scripting (XSS), and others defined by common security standards .

The project scanner properties optimize Java code analysis in the SonarQube environment by specifying crucial paths and settings such as 'sonar.java.binaries', 'sonar.java.libraries', and 'sonar.java.source' to ensure the correct resolution of dependencies and standards for code compilation. Additionally, exclusions are set in 'sonar.coverage.exclusions' to streamline the analysis process by skipping certain directories or files that are not relevant for code quality metrics, helping focus the analysis on core code areas .

The SonarQube server configuration impacts the security of GitHub and GitLab user signups by controlling whether users can sign up using these services. The settings 'sonar.auth.github.allowUsersToSignUp=false' and 'sonar.auth.gitlab.allowUsersToSignUp=false' indicate that new user signups through GitHub and GitLab are not allowed, enhancing security by limiting the means of authentication to only pre-approved or internal methods .

The JaCoCo plugin plays a critical role in Java project testing and coverage reporting within SonarQube. It is identified by 'sonar.coverage.jacoco.xmlReportPaths', providing paths to XML reports generated by JaCoCo after running unit tests. This integration enables detailed test coverage analysis beyond mere execution counts, offering insights into which parts of the codebase remain untested. Additionally, by linking with the configuration 'sonar.java.coveragePlugin=jacoco', it ensures Java code is aptly covered and helps optimize the effort to reach specific coverage rates .

Enabling 'sonar.forceAuthentication=true' in SonarQube configurations has significant security implications by enforcing that all users be authenticated before accessing the SonarQube instance. This setting mitigates unauthorized access, ensuring that project data and analytics are only available to legitimate users. It enhances security by integrating with LDAP or other authentication mechanisms to validate user credentials .

Specific code exclusions in 'sonar.coverage.exclusions' can significantly impact the analysis of Java projects by omitting particular files or directories from test coverage calculations. This may be necessary to remove boilerplate code, third-party libraries, or non-business logic components from skewing coverage metrics, allowing developers to concentrate on critical areas of the application. However, excessive or poorly planned exclusions can lead to underestimation of coverage, potentially obscuring areas that genuinely need improvement [So...

You might also like