·
41 commits
to master
since this release
Immutable
release. Only release title and notes can be modified.
SonarQube CLI v1.9.0
This release ships new commands such as sonar import or sonar stats command, supports global integrate by default, features a batch of quality-of-life improvements across commands and output, and several bug fixes and security hardening items.
Features
sonar integratenow operates at the global level: The integration framework has been redesigned to configure integrations globally across all projects rather than per-project. This unifies configuration, reduces duplication, and simplifies management. On first run of v1.9.0, an automatic migration cleans up any existing project-level integration artifacts and moves them to the global configuration. If the project key cannot be auto-discovered, run sonar link in your project directory to connect it to SonarQube.sonar importis now available in Open Beta: Thesonar importcommand allows to import repositories from a connected DevOps platform into SonarQube.sonar statscommand (Alpha): A newsonar statscommand displays a local summary of your SonarQube CLI usage — commands run, analyses performed, and more. Supports--jsonoutput and a--sincewindow (7d, 14d, 30d, all). Raw event data older than one year is automatically purged while aggregates are retained for all-time reporting. Stats collection is controlled by its own dedicated consent flag, independent of the general telemetry opt-in, since this data is consumed locally only.sonar update statussubcommand:sonar update --statushas been promoted to a propersonar update statussubcommand for consistency withsonar auth statusandsonar system status. The new subcommand also gains--formatsupport for JSON output.sonar auth login --with-token: You can now pass a token directly tosonar auth loginvia the--with-tokenflag, enabling non-interactive authentication flows.- Consistent
--formatflag: All data commands now accept a uniform--formatflag for JSON output. - GitLab CI custom job template:
sonar admin onboard-ci gitlabnow accepts a--job-template <file>flag, letting you inject your own YAML job definition instead of the default template. - Organization membership mismatch warning:
sonar auth statusnow reports a clear diagnostic when your token has no membership for the configured organization, instead of silently showingConnectedwhile features like Vortex are unavailable.
Bug Fixes
- Pre-push hook scan scope: Fixed an issue where the pre-push hook defaulted to a full repository scan when it should have scanned only the changed files.
- Vortex keep/remove decision: Fixed a bug where declining to keep an already-installed Vortex on re-run would remove the top-level feature but silently reinstall it because sibling hook features (e.g. Claude's
PostToolUsedispatch, Codex's SQAA subfeature) re-derived the install decision independently. All Vortex-gated features now agree on a single keep/remove answer. - Server URL validation: Server URLs are now validated to confirm they are actually URLs, not just checked for the absence of line breaks.
- Line break rejection: Server URLs and project keys containing line breaks are now rejected at resolution time — at
sonar auth login, via environment variable, or via--project— with a clear error pointing at the correct fix. - Error logging: Fixed a bug where swallowed errors were logged as
{}in the file log instead of their actual cause, making several silent failure paths undiagnosable. - No-project-key messages: Messages shown when no project key is configured now point users at
sonar link <projectKey>instead of the outdatedsonar-project.properties/.sonarlintreferences. - Integration copy and warnings: Clarified several integration and migration messages that described what went wrong but not what to do — hook-conflict warnings and migration notices now include actionable next steps.
Security
- OAuth loopback hardening: The OAuth callback during
sonar auth loginnow requires both127.0.0.1and::1to bind each candidate port, preventing a local process from occupying the IPv6 loopback port and intercepting the OAuth token on systems where browsers prefer IPv6 forlocalhost. - Authentication callback hardening: Tightened browser authentication callback acceptance and state validation to address issues identified by SonarQube analysis.
Miscellaneous
- Organization details are now resolved through the public organizations API rather than an internal, undocumented endpoint.
- Crash reports sent to Sentry now route through the configured proxy and CA certificate, restoring error visibility for installations behind mandatory corporate proxies.
- The
CliCommandExecutedtelemetry event now captures which flags and options were used in each invocation. - Internal refactors and dependency bumps.