Repository navigation
Expand file tree
/
Copy pathsonar-project.properties
More file actions
38 lines (38 loc) · 2.34 KB
/
Copy pathsonar-project.properties
File metadata and controls
38 lines (38 loc) · 2.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
# SonarCloud automatic-analysis configuration.
# Scope the quality gate to the shipped library (src/), so it reflects product
# code quality, not pedantry in tests, CI helper scripts, docs, benchmarks, or
# examples. Coverage is gated locally per file in CI (scripts/coverage_per_file.py),
# so Sonar is a non-blocking quality and security dashboard, not a merge gate.
sonar.projectKey=astrogilda_tsbootstrap
sonar.organization=astrogilda
sonar.sources=src
sonar.tests=tests
sonar.python.version=3.10, 3.11, 3.12, 3.13, 3.14
# Neither of the two scope settings above reaches .github/**, and this file cannot
# make it do so. Automatic analysis ignores sonar.sources, and adding .github/** to
# sonar.exclusions was tried on this branch and changed nothing: the analysis still
# reported every GitHub Actions rule hit in the workflow directory. Scope for
# automatic analysis lives in the SonarCloud project settings, under Administration,
# Analysis Scope.
#
# THAT SETTING IS NOW IN PLACE, set server-side on 2026-08-27 to
# .github/**,docs/**,benchmarks/**,scripts/**,tools/**,examples/**
# It was set through the web API rather than the UI (POST api/settings/set with
# component=astrogilda_tsbootstrap and key=sonar.exclusions, which returns 204 and
# reads back), so a project administrator can reproduce or revert it without
# clicking. The server-side list is the one that governs; the sonar.exclusions line
# at the foot of this file is inert under automatic analysis and is kept only so the
# intent is visible to a reader of the repository. If the two ever disagree, the
# server wins and this file is the stale copy.
#
# This matters because rules githubactions:S8541 and S8544 entered the profile after
# the last analysis of main on 2026-07-15 and now report on CI plumbing this gate was
# never scoped to cover. S8544 is satisfied: every uv invocation in CI.yml passes
# --locked. S8541 asks for --no-build, which this project cannot use, because uv sync
# installs the project itself and refuses under that flag with "can't be installed
# because it is marked as --no-build but has no binary distribution".
#
# Workflow security keeps a dedicated owner regardless: OpenSSF Scorecard
# (.github/workflows/scorecard.yml) audits action pinning, token permissions and
# dangerous patterns on every push to main.
sonar.exclusions=docs/**,benchmarks/**,scripts/**,tools/**,examples/**