Skip to content

1.8.0.5274

Choose a tag to compare

@github-actions github-actions released this 15 Sep 07:58
· 105 commits to master since this release
Immutable release. Only release title and notes can be modified.
25e2937

SonarQube CLI v1.8.0

This release significantly expands the sonar quality-gate status command with drill-down enrichment, introduces sonar link for manual project binding, and brings several quality-of-life improvements across issue listing, authentication, and agentic integrations.

Features

  • Quality Gate drill-down enrichment: sonar quality-gate status now supports --category <coverage|duplications|issues|security|dependency-risks> and --top <N> flags to show the worst-N files or issues behind each failing condition, making it actionable at a glance.
    • Coverage: shows the worst files by coverage value for failing coverage conditions.
    • Duplications: shows the worst files by duplication metric for failing duplications conditions.
    • Issues, Reliability & Maintainability: shows the worst bugs, code smells, and violations for failing issue-count and rating conditions.
    • Security: shows the worst vulnerabilities for failing security conditions.
    • Dependency Risks: shows the worst SCA dependency risks (malware, prohibited licenses, vulnerabilities) for failing SCA conditions.
  • Quality Gate file drill-down: sonar quality-gate status <file> narrows the quality gate view to a single file or directory, showing only the conditions and issues relevant to that path. Use --all to also show passing conditions.
  • PR auto-resolution: sonar quality-gate status now automatically resolves the pull request for the current branch via SonarQube's API when neither --branch nor --pull-request is specified.
  • Issue filtering by file or directory: sonar list issues now accepts a --file <path> flag to scope results to a single file or directory without going through the quality gate.
  • Open/confirmed issues by default: sonar list issues now returns only open and confirmed issues by default, matching the most common use case. Previously no status filter was applied.
  • sonar link <project-key> command: new command that writes a local binding file for the current directory, letting you manually associate a repository with a SonarQube project key when auto-discovery cannot find one.
  • Auth warning on login with env vars: sonar auth login now displays a clear warning when authentication environment variables are already set, explaining that they will continue to take precedence and that sonar auth status can be used to inspect the current connection.
  • Agentic analysis quieted when no project is configured: when no project is linked, sonar analyze agentic no longer emits a distracting skip message on every turn; the agent is instructed to discard the output silently.
  • Vortex (Agentic Analysis) now works at global scope: sonar integrate claude -g (and other global integrations) now installs Vortex analysis hooks correctly, without requiring a project directory. Project resolution happens at runtime.
  • Context Augmentation delivered via session-start hook: Vortex context is now delivered through the agent's session-start hook rather than a static SKILL.md file, removing the project-scope constraint and leaving no stale file on disk from previous installs.
  • Onboard CI GitLab (alpha): added sonar admin onboard-ci gitlab command for setting up GitLab CI integration.
  • Successful import links to project list: after a successful project import, the CLI now links to the project list page rather than the (not-yet-ready) dashboard.

Bug Fixes

  • Issue search parameters fixed: sonar list issues was sending incorrect query parameters to the SonarQube API — on SonarQube Cloud the project filter was silently dropped, and on SonarQube Server the new-code period filter was a no-op since Server 10.0. Both are now fixed. The minimum supported SonarQube Server version is raised to 25.1.
  • Change-set path validation: paths in the change set are now validated against the repository boundary before file inspection, preventing traversal outside the repository root.

Miscellaneous

  • Continued foundational work on the agentic integrations architecture: centralized auth resolution, agent-session-start hook handler, and MCP configuration test coverage for global-scope installs.
  • Extensive internal refactoring of the HTTP client layer (Result monad propagation, domain API clients, SonarHttpClient extraction) and the console/UI wrapper, with no user-visible behavior change.
  • Internal dependency bumps and code health improvements.