ci: drop the sonar job and its config !444

merged merged by cmc on 2026-09-20 06:28 UTC · krz/gitbay:drop-sonar into main

Discussion

cmc

The SonarCloud project is deleted, so both are dead weight.

  • sonar-project.properties removed.
  • The sonar job removed from .gitbay/ci.yml. Nightly at 30 3, it would fetch the ~50MB scanner and report to a project that is not there; || true means it never went red about it.

internal/ci.Parse on the edited file yields exactly build, test and vuln, checked with a throwaway test that is not part of this change.

Left alone on purpose: the four incidental mentions in comments (cmd/gitbay-runner/isolate.go:157, main.go:316, env_test.go:83 name the scanner as an example of what the build cache holds; internal/httpd/inputlabels_test.go:25 records why that test exists) and the CHANGELOG history.

Two things this MR cannot do

  • The SONAR_TOKEN build secret on this repository is now unused.
  • Deleting the project did not revoke the token it holds. It is a SonarCloud user token, not project-scoped, and it still authenticates:

    api/authentication/validate      -> {"valid":true}
    api/projects/search?org=krz      -> 0 projects
    

    It should be revoked at sonarcloud.io under Account → Security, and removed from the copy in this repository's CLAUDE.md.