Skip to content

1.9.0.15656

Latest

Choose a tag to compare

@github-actions github-actions released this 29 Sep 14:55
· 41 commits to master since this release
Immutable release. Only release title and notes can be modified.
4eabd67

SonarQube CLI v1.9.0

This release ships new commands such as sonar import or sonar stats command, supports global integrate by default, features a batch of quality-of-life improvements across commands and output, and several bug fixes and security hardening items.

Features

  • sonar integrate now operates at the global level: The integration framework has been redesigned to configure integrations globally across all projects rather than per-project. This unifies configuration, reduces duplication, and simplifies management. On first run of v1.9.0, an automatic migration cleans up any existing project-level integration artifacts and moves them to the global configuration. If the project key cannot be auto-discovered, run sonar link in your project directory to connect it to SonarQube.
  • sonar import is now available in Open Beta: The sonar import command allows to import repositories from a connected DevOps platform into SonarQube.
  • sonar stats command (Alpha): A new sonar stats command displays a local summary of your SonarQube CLI usage — commands run, analyses performed, and more. Supports --json output and a --since window (7d, 14d, 30d, all). Raw event data older than one year is automatically purged while aggregates are retained for all-time reporting. Stats collection is controlled by its own dedicated consent flag, independent of the general telemetry opt-in, since this data is consumed locally only.
  • sonar update status subcommand: sonar update --status has been promoted to a proper sonar update status subcommand for consistency with sonar auth status and sonar system status. The new subcommand also gains --format support for JSON output.
  • sonar auth login --with-token: You can now pass a token directly to sonar auth login via the --with-token flag, enabling non-interactive authentication flows.
  • Consistent --format flag: All data commands now accept a uniform --format flag for JSON output.
  • GitLab CI custom job template: sonar admin onboard-ci gitlab now accepts a --job-template <file> flag, letting you inject your own YAML job definition instead of the default template.
  • Organization membership mismatch warning: sonar auth status now reports a clear diagnostic when your token has no membership for the configured organization, instead of silently showing Connected while features like Vortex are unavailable.

Bug Fixes

  • Pre-push hook scan scope: Fixed an issue where the pre-push hook defaulted to a full repository scan when it should have scanned only the changed files.
  • Vortex keep/remove decision: Fixed a bug where declining to keep an already-installed Vortex on re-run would remove the top-level feature but silently reinstall it because sibling hook features (e.g. Claude's PostToolUse dispatch, Codex's SQAA subfeature) re-derived the install decision independently. All Vortex-gated features now agree on a single keep/remove answer.
  • Server URL validation: Server URLs are now validated to confirm they are actually URLs, not just checked for the absence of line breaks.
  • Line break rejection: Server URLs and project keys containing line breaks are now rejected at resolution time — at sonar auth login, via environment variable, or via --project — with a clear error pointing at the correct fix.
  • Error logging: Fixed a bug where swallowed errors were logged as {} in the file log instead of their actual cause, making several silent failure paths undiagnosable.
  • No-project-key messages: Messages shown when no project key is configured now point users at sonar link <projectKey> instead of the outdated sonar-project.properties/.sonarlint references.
  • Integration copy and warnings: Clarified several integration and migration messages that described what went wrong but not what to do — hook-conflict warnings and migration notices now include actionable next steps.

Security

  • OAuth loopback hardening: The OAuth callback during sonar auth login now requires both 127.0.0.1 and ::1 to bind each candidate port, preventing a local process from occupying the IPv6 loopback port and intercepting the OAuth token on systems where browsers prefer IPv6 for localhost.
  • Authentication callback hardening: Tightened browser authentication callback acceptance and state validation to address issues identified by SonarQube analysis.

Miscellaneous

  • Organization details are now resolved through the public organizations API rather than an internal, undocumented endpoint.
  • Crash reports sent to Sentry now route through the configured proxy and CA certificate, restoring error visibility for installations behind mandatory corporate proxies.
  • The CliCommandExecuted telemetry event now captures which flags and options were used in each invocation.
  • Internal refactors and dependency bumps.