#sonarcloud

2024-10-28

Is it a trend that cloud services have less features than their on-premise counterparts? Today I am struggling with the #Azure container registry cache, which does not support pulling new tags automatically, which makes it unusable for #Renovate. #Bitbucket cloud does not have the feature to delete PRs. Same was when #SonarQube became #SonarCloud - so many useful features where suddenly missing.

#DevOps #cloud #dev

Marnix van Valenmarnix@hachyderm.io
2024-09-24

Ah crap, #SonarCloud is down. So much for getting shit done today 😞

Peter Toft JΓΈlvingjoelving@mastodon.joelving.dk
2024-07-11

What's your favorite tool or method of securing 3rd party packages against vulnerabilities, "supply chain attacks", and malicious packages in a #dotnet, #javascript and #Docker / #Kubernetes setting?

Is it #Snyk, #FOSSA, #SonarQube / #SonarCloud, or something else entirely?

Boosts and recommendations highly appreciated. πŸ™

πŸ›‘ H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-12-14

"πŸ”₯ pfSense Security Alert: Critical Vulnerabilities Uncovered by SonarCloud πŸ›‘οΈ"

SonarCloud's vigilant scanning reveals two critical vulnerabilities in pfSense, a widely used open-source firewall: XSS (CVE-2023-42325) and Command Injection (CVE-2023-42326). These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on pfSense appliances, highlighting the importance of continuous security vigilance even within trusted network perimeters. Thanks to swift action by Netgate, patches are now available. A reminder to always keep your systems updated!

πŸ“š Source: Oskar Zeino-Mahmalat's article on SonarSource SonarSource Blog

Tags: #pfSense #Cybersecurity #Vulnerabilities #XSS #CommandInjection #Netgate #SonarCloud #SecurityPatch πŸš¨πŸ”’πŸ’»

Denis TrollerDenisTroller
2023-12-07

Hey, fellow developers! I am happy to announce that now helps find related bugs in your code.
Check it out at t.ly/h1aXG!, and enroll your project at sonarcloud.io, it's free for open-source projects.

2023-11-14

I just updated my GitHub Action "sonarscan-dotnet" for #DotNet 8. Easy #SonarCloud or #SonarQube code quality scanning in GitHub workflows for .NET projects.
github.com/marketplace/actions

Denis TrollerDenisTroller
2023-11-07

I am very happy to announce that and now support the upcoming & a full week before their release!

Find out more on community.sonarsource.com/t/ne

2023-10-09

ugh, trying for days now to find out why my phpunit tests do not provide coverage for #sonarcloud
Slowly getting the feeling I managed to create a special case of phpunit config, which makes matching the code for the coverage not working in special circumstances.

but running it local with identic versions does work πŸ™„
#php

2023-10-07

Focusing on the important parts during the weekend πŸ˜ƒ

#Python #CodeScene #SonarCloud #Polylith

github.com/DavidVujic/python-p

CodeScene Code Health view: score 10 out of 10.SonarCloud quality gate: 0% duplications.
Emelia πŸ‘ΈπŸ»thisismissem@hachyderm.io
2023-07-26

Oooh! JetBrains Qodana looks like a nice alternative to #SonarCloud for code metrics/scanning: jetbrains.com/qodana/

2023-02-26

I've tried #sonarcloud for my pyp-boy repository. It's a nicely simplified #sonarqube interface but the added value is still present with the hints and how-to fix helps.

Fixed all issues in a couple of minutes, yeay \o/

Sonarcloud screenshot with issues fixed
Arda Kılıçdağıarda@micro.arda.pw
2023-01-16

The very question that we've been asking for:

#pipeline #devops #books #deployment #cicd #sonarcloud #bitbucket

Gabriel Ricardgr@mas.to
2023-01-05

Trying to get #jest #unittest #coverage run in #CircleCI (with parallelism, so it runs faster) and then results reported to #SonarCloud is quite a challenge. There’s a fair amount of blog posts, docs & SO threads that cover individual parts, but not the whole solution.

2022-12-30

git commit -m "Not happy about this but I'm excluding some more code from coverage analysis."

#ItsFridayAfternoonForPetesSake #git #coverage #codeCoverage #sonarCloud

2022-12-02

aha! Maybe it's because we have a different workflow configured for our main branch vs development branches! #CircleCI #Sonarcloud #ItsFridayAfternoonAfterFiveWhyAmIStillBangingMyHeadAgainstThis #BecauseItBugsMeWhenThingsAreBroken

Brian :fedora: :python:bpepple@fosstodon.org
2020-10-12

Spent *way* longer than planned setting up a #github action for #SonarCloud. Oh well, time to get some much needed #caffeine.

Arghya :apple_inc: :debian:arghyadeep@fosstodon.org
2020-09-23

Implemented #SonarCloud in one of my #npm projects and it gave me such a hard time failing the scans.

Finally managed to get 94.4% code coverage with 0 issues.

It's a really great tool to detect bugs and the minor code smells you might have easily overlooked and improves the quality of your code drastically.

#npm #nodejs #javascript #sonar #SonarCloud #codeQuality #codeCoverage #cicd #devops

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst