The SonarCloud project is deleted, so both are dead weight.
sonar-project.propertiesremoved.- The
sonarjob removed from.gitbay/ci.yml. Nightly at 30 3, it would fetch the ~50MB scanner and report to a project that is not there;|| truemeans it never went red about it.
internal/ci.Parse on the edited file yields exactly build, test
and vuln, checked with a throwaway test that is not part of this
change.
Left alone on purpose: the four incidental mentions in comments
(cmd/gitbay-runner/isolate.go:157, main.go:316, env_test.go:83
name the scanner as an example of what the build cache holds;
internal/httpd/inputlabels_test.go:25 records why that test exists)
and the CHANGELOG history.
Two things this MR cannot do
- The
SONAR_TOKENbuild secret on this repository is now unused. -
Deleting the project did not revoke the token it holds. It is a SonarCloud user token, not project-scoped, and it still authenticates:
api/authentication/validate -> {"valid":true} api/projects/search?org=krz -> 0 projectsIt should be revoked at sonarcloud.io under Account → Security, and removed from the copy in this repository's CLAUDE.md.