# SonarCloud analysis. Only SONAR_TOKEN is a secret; it is a gitbay build # secret (`repo secret set krz/gitbay SONAR_TOKEN`, value on stdin) and # never appears here. Everything below is public configuration and is # checked in so a scan is reproducible from the repository alone. sonar.organization=krz sonar.projectKey=krz_gitbay sonar.projectName=gitbay sonar.sources=. sonar.tests=. sonar.test.inclusions=**/*_test.go # dist/ is release output, testdata is fixtures meant to be malformed, and # the fonts are third-party binaries. # # The migrations are excluded because they are SQLite and the analyser # reads .sql as PL/SQL, where '' is NULL. That turns `WHERE col = ''` on a # NOT NULL DEFAULT '' column — correct SQLite, and the shape used # throughout — into a NullComparison finding. Excluding them is the fix; # dismissing the same false positive after every migration is not. sonar.exclusions=dist/**,**/testdata/**,internal/web/static/fonts/**,internal/store/migrations/** # No sonar.go.coverage.reportPaths yet. Most of this repository's coverage # comes from the e2e suite, and re-running that under -coverprofile would # double the CI time; unit-only coverage would report misleadingly low # numbers for packages e2e exercises heavily. Reporting none is more # honest than reporting the wrong number.