1.8.0.5274
·
105 commits
to master
since this release
Immutable
release. Only release title and notes can be modified.
SonarQube CLI v1.8.0
This release significantly expands the sonar quality-gate status command with drill-down enrichment, introduces sonar link for manual project binding, and brings several quality-of-life improvements across issue listing, authentication, and agentic integrations.
Features
- Quality Gate drill-down enrichment:
sonar quality-gate statusnow supports--category <coverage|duplications|issues|security|dependency-risks>and--top <N>flags to show the worst-N files or issues behind each failing condition, making it actionable at a glance.- Coverage: shows the worst files by coverage value for failing coverage conditions.
- Duplications: shows the worst files by duplication metric for failing duplications conditions.
- Issues, Reliability & Maintainability: shows the worst bugs, code smells, and violations for failing issue-count and rating conditions.
- Security: shows the worst vulnerabilities for failing security conditions.
- Dependency Risks: shows the worst SCA dependency risks (malware, prohibited licenses, vulnerabilities) for failing SCA conditions.
- Quality Gate file drill-down:
sonar quality-gate status <file>narrows the quality gate view to a single file or directory, showing only the conditions and issues relevant to that path. Use--allto also show passing conditions. - PR auto-resolution:
sonar quality-gate statusnow automatically resolves the pull request for the current branch via SonarQube's API when neither--branchnor--pull-requestis specified. - Issue filtering by file or directory:
sonar list issuesnow accepts a--file <path>flag to scope results to a single file or directory without going through the quality gate. - Open/confirmed issues by default:
sonar list issuesnow returns only open and confirmed issues by default, matching the most common use case. Previously no status filter was applied. sonar link <project-key>command: new command that writes a local binding file for the current directory, letting you manually associate a repository with a SonarQube project key when auto-discovery cannot find one.- Auth warning on login with env vars:
sonar auth loginnow displays a clear warning when authentication environment variables are already set, explaining that they will continue to take precedence and thatsonar auth statuscan be used to inspect the current connection. - Agentic analysis quieted when no project is configured: when no project is linked,
sonar analyze agenticno longer emits a distracting skip message on every turn; the agent is instructed to discard the output silently. - Vortex (Agentic Analysis) now works at global scope:
sonar integrate claude -g(and other global integrations) now installs Vortex analysis hooks correctly, without requiring a project directory. Project resolution happens at runtime. - Context Augmentation delivered via session-start hook: Vortex context is now delivered through the agent's session-start hook rather than a static
SKILL.mdfile, removing the project-scope constraint and leaving no stale file on disk from previous installs. - Onboard CI GitLab (alpha): added
sonar admin onboard-ci gitlabcommand for setting up GitLab CI integration. - Successful import links to project list: after a successful project import, the CLI now links to the project list page rather than the (not-yet-ready) dashboard.
Bug Fixes
- Issue search parameters fixed:
sonar list issueswas sending incorrect query parameters to the SonarQube API — on SonarQube Cloud the project filter was silently dropped, and on SonarQube Server the new-code period filter was a no-op since Server 10.0. Both are now fixed. The minimum supported SonarQube Server version is raised to 25.1. - Change-set path validation: paths in the change set are now validated against the repository boundary before file inspection, preventing traversal outside the repository root.
Miscellaneous
- Continued foundational work on the agentic integrations architecture: centralized auth resolution,
agent-session-starthook handler, and MCP configuration test coverage for global-scope installs. - Extensive internal refactoring of the HTTP client layer (Result monad propagation, domain API clients,
SonarHttpClientextraction) and the console/UI wrapper, with no user-visible behavior change. - Internal dependency bumps and code health improvements.