sonar-project.properties

v1.22.1
gitbay/sonar-project.properties history · blame · raw

27 lines · 1326 bytes

 1# SonarCloud analysis. Only SONAR_TOKEN is a secret; it is a gitbay build
 2# secret (`repo secret set krz/gitbay SONAR_TOKEN`, value on stdin) and
 3# never appears here. Everything below is public configuration and is
 4# checked in so a scan is reproducible from the repository alone.
 5sonar.organization=krz
 6sonar.projectKey=krz_gitbay
 7sonar.projectName=gitbay
 8
 9sonar.sources=.
10sonar.tests=.
11sonar.test.inclusions=**/*_test.go
12
13# dist/ is release output, testdata is fixtures meant to be malformed, and
14# the fonts are third-party binaries.
15#
16# The migrations are excluded because they are SQLite and the analyser
17# reads .sql as PL/SQL, where '' is NULL. That turns `WHERE col = ''` on a
18# NOT NULL DEFAULT '' column — correct SQLite, and the shape used
19# throughout — into a NullComparison finding. Excluding them is the fix;
20# dismissing the same false positive after every migration is not.
21sonar.exclusions=dist/**,**/testdata/**,internal/web/static/fonts/**,internal/store/migrations/**
22
23# No sonar.go.coverage.reportPaths yet. Most of this repository's coverage
24# comes from the e2e suite, and re-running that under -coverprofile would
25# double the CI time; unit-only coverage would report misleadingly low
26# numbers for packages e2e exercises heavily. Reporting none is more
27# honest than reporting the wrong number.