audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 4aa28faec7

4aa28faec7d6b311fde98324851aa37d8d798984

parent: 5834e7402e

Unsigned

cmc <hello@cleberg.net> · 2026-07-29 04:29 UTC

chore: suppress S1172 on collectors via sonar-project.properties

The GitLab (and GitHub) collectors share a uniform (id, cfg, cache) signature
so the audit runner can dispatch every check identically; some collectors use
only part of it. Ignore python:S1172 (unused parameter) on the collector
packages rather than diverging their signatures.

Kept minimal for SonarCloud Automatic Analysis: no projectKey/organization,
which are bound by the GitHub integration.

Layout: unified · split

sonar-project.properties added +15
@@ -0,0 +1,15 @@
1# SonarCloud configuration (Automatic Analysis / Autoscan).
2#
3# projectKey and organization are intentionally omitted — they are bound
4# automatically by the GitHub integration, and setting them here can disable
5# Automatic Analysis.
6
7# Suppress python:S1172 (unused function parameter) on the collector packages.
8# Collectors share a uniform (id, cfg, cache) signature so the audit runner can
9# dispatch every check the same way. Some collectors legitimately use only part
10# of that signature — per-project collectors don't need the org/group, and the
11# pure formatter needs only the cache. This mirrors the existing GitHub
12# collectors (e.g. privileged_access, permission_matrix).
13sonar.issue.ignore.multicriteria=e1
14sonar.issue.ignore.multicriteria.e1.ruleKey=python:S1172
15sonar.issue.ignore.multicriteria.e1.resourcePath=applications/**/collectors/**/*.py