Skip to content

1.7.0.4638

Choose a tag to compare

@github-actions github-actions released this 31 Aug 13:12
· 146 commits to master since this release
Immutable release. Only release title and notes can be modified.

SonarQube CLI v1.7.0

This release introduces the sonar quality-gate command for checking your project's Quality Gate status from the terminal, improves git hook chaining, fixes several bugs, and includes a range of internal improvements.

Features

  • Quality Gate status command: New sonar quality-gate status command (also accessible as sonar qg status) displays your project's Quality Gate verdict directly from the terminal. Reports OK, ERROR with a list of failing conditions, or Not computed with a hint to run sonar analyze. Exits with a distinct code for each outcome.
  • sonar context is now stable: The sonar context command is promoted from Open Beta to stable — the [BETA] label and beta warning are removed, and the command appears in root help like any other GA command.
  • Global git hook chaining: When sonar integrate git is installed globally (via core.hooksPath), Sonar's hook scripts now detect and chain to any pre-existing local .git/hooks/<name> script in each repository, so hand-written hooks and other hook frameworks are no longer silently bypassed.
  • Vortex entitlement check on SonarQube Server: The CLI now queries the SonarQube Server CAG Hub to determine whether Vortex (Agentic Analysis) is licensed, rather than always returning not_applicable for non-Cloud connections.
  • Staged command options: Command options can now be individually marked as alpha or beta, respecting the same visibility and entitlement rules as staged commands.

Bug Fixes

  • MCP config on Windows: sonar integrate commands no longer write sonar.exe as the MCP server command on Windows. The generated .mcp.json now uses sonar, which works cross-platform and is safe to commit in mixed-OS teams.
  • Custom SONAR_USER_HOME in MCP config: When SONAR_USER_HOME is set to a non-default path, sonar integrate now includes it in the generated MCP server entry so the MCP process can find CLI state and authenticate correctly — previously users had to hand-edit the config.
  • Claude Code hook path anchoring: Project-scope Claude Code hook commands are now anchored to ${CLAUDE_PROJECT_DIR} instead of the current working directory, preventing hook failures when the working directory diverges from the project root (e.g. in worktrees).
  • Hook stdin listener leak on timeout: A timed-out stdin read in hook scripts no longer keeps the process alive indefinitely; listeners are now properly cleaned up so the process exits as expected.
  • Binary install robustness: The CLI no longer fails a binary installation when the installed binary's version output doesn't match an expected format. The spawned binary is verified to exit successfully, but version-string parsing is no longer required.
  • Shared binaries no longer deleted on feature removal: Removing an integration feature no longer deletes a shared binary (e.g. sonar-secrets or sca-scanner-cli) that may still be in use by another flow such as sonar analyze secrets. Previously this could trigger an unexpected re-download on next use.

Miscellaneous

  • Internal telemetry improvements: agent session IDs are now resolved from agent-native environment sources and included in CLI telemetry events; the invocation ID is forwarded to Vortex analysis requests; telemetry emission is deferred to post-command processing for cleaner enrichment.
  • Foundational work on unified project-key resolution and installed-agent discovery, supporting upcoming improvements to sonar integrate.
  • Internal refactors and dependency bumps.