1.7.0.4638
·
146 commits
to master
since this release
Immutable
release. Only release title and notes can be modified.
SonarQube CLI v1.7.0
This release introduces the sonar quality-gate command for checking your project's Quality Gate status from the terminal, improves git hook chaining, fixes several bugs, and includes a range of internal improvements.
Features
- Quality Gate status command: New
sonar quality-gate statuscommand (also accessible assonar qg status) displays your project's Quality Gate verdict directly from the terminal. ReportsOK,ERRORwith a list of failing conditions, orNot computedwith a hint to runsonar analyze. Exits with a distinct code for each outcome. sonar contextis now stable: Thesonar contextcommand is promoted from Open Beta to stable — the[BETA]label and beta warning are removed, and the command appears in root help like any other GA command.- Global git hook chaining: When
sonar integrate gitis installed globally (viacore.hooksPath), Sonar's hook scripts now detect and chain to any pre-existing local.git/hooks/<name>script in each repository, so hand-written hooks and other hook frameworks are no longer silently bypassed. - Vortex entitlement check on SonarQube Server: The CLI now queries the SonarQube Server CAG Hub to determine whether Vortex (Agentic Analysis) is licensed, rather than always returning
not_applicablefor non-Cloud connections. - Staged command options: Command options can now be individually marked as alpha or beta, respecting the same visibility and entitlement rules as staged commands.
Bug Fixes
- MCP config on Windows:
sonar integratecommands no longer writesonar.exeas the MCP server command on Windows. The generated.mcp.jsonnow usessonar, which works cross-platform and is safe to commit in mixed-OS teams. - Custom
SONAR_USER_HOMEin MCP config: WhenSONAR_USER_HOMEis set to a non-default path,sonar integratenow includes it in the generated MCP server entry so the MCP process can find CLI state and authenticate correctly — previously users had to hand-edit the config. - Claude Code hook path anchoring: Project-scope Claude Code hook commands are now anchored to
${CLAUDE_PROJECT_DIR}instead of the current working directory, preventing hook failures when the working directory diverges from the project root (e.g. in worktrees). - Hook stdin listener leak on timeout: A timed-out stdin read in hook scripts no longer keeps the process alive indefinitely; listeners are now properly cleaned up so the process exits as expected.
- Binary install robustness: The CLI no longer fails a binary installation when the installed binary's version output doesn't match an expected format. The spawned binary is verified to exit successfully, but version-string parsing is no longer required.
- Shared binaries no longer deleted on feature removal: Removing an integration feature no longer deletes a shared binary (e.g.
sonar-secretsorsca-scanner-cli) that may still be in use by another flow such assonar analyze secrets. Previously this could trigger an unexpected re-download on next use.
Miscellaneous
- Internal telemetry improvements: agent session IDs are now resolved from agent-native environment sources and included in CLI telemetry events; the invocation ID is forwarded to Vortex analysis requests; telemetry emission is deferred to post-command processing for cleaner enrichment.
- Foundational work on unified project-key resolution and installed-agent discovery, supporting upcoming improvements to
sonar integrate. - Internal refactors and dependency bumps.