{"id":17956836,"url":"https://github.com/mc1arke/sonarqube-community-branch-plugin","last_synced_at":"2026-02-28T18:01:06.335Z","repository":{"id":37442870,"uuid":"173807249","full_name":"mc1arke/sonarqube-community-branch-plugin","owner":"mc1arke","description":"A plugin that allows branch analysis and pull request decoration in the Community version of Sonarqube","archived":false,"fork":false,"pushed_at":"2026-02-28T09:24:28.000Z","size":1737,"stargazers_count":2677,"open_issues_count":2,"forks_count":585,"subscribers_count":91,"default_branch":"master","last_synced_at":"2026-02-28T14:39:52.556Z","etag":null,"topics":["sonarqube","sonarqube-analysis","sonarqube-plugin","sonarqube-scanner","sonarqube-server"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"lgpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mc1arke.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":["mc1arke"]}},"created_at":"2019-03-04T19:24:36.000Z","updated_at":"2026-02-28T09:24:32.000Z","dependencies_parsed_at":"2022-07-19T02:32:06.262Z","dependency_job_id":"9f72ec97-46f2-4330-a65a-cf1ec1e83018","html_url":"https://github.com/mc1arke/sonarqube-community-branch-plugin","commit_stats":{"total_commits":361,"total_committers":59,"mean_commits":6.11864406779661,"dds":0.5373961218836565,"last_synced_commit":"898ebdd24a982ad2e0409c20e5763b3b72e8614e"},"previous_names":[],"tags_count":46,"template":false,"template_full_name":null,"purl":"pkg:github/mc1arke/sonarqube-community-branch-plugin","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mc1arke%2Fsonarqube-community-branch-plugin","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mc1arke%2Fsonarqube-community-branch-plugin/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mc1arke%2Fsonarqube-community-branch-plugin/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mc1arke%2Fsonarqube-community-branch-plugin/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mc1arke","download_url":"https://codeload.github.com/mc1arke/sonarqube-community-branch-plugin/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mc1arke%2Fsonarqube-community-branch-plugin/sbom","scorecard":{"id":10768,"data":{"date":"2025-08-04","repo":{"name":"github.com/mc1arke/sonarqube-community-branch-plugin","commit":"b9bc854c3c7f261ee1f83041d7f496f464cb8b25"},"scorecard":{"version":"v5.2.1-28-gc1d103a9","commit":"c1d103a9bb9f635ec7260bf9aa0699466fa4be0e"},"score":4.9,"checks":[{"name":"Code-Review","score":1,"reason":"Found 3/23 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#packaging"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:16","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:17","Warn: no topLevel permission defined: .github/workflows/build.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: gradle/wrapper/gradle-wrapper.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:165: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/build.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/mc1arke/sonarqube-community-branch-plugin/codeql-analysis.yml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:4","Warn: containerImage not pinned by hash: Dockerfile:12","Warn: containerImage not pinned by hash: Dockerfile:23","Warn: containerImage not pinned by hash: release.Dockerfile:3","Info:   0 out of  21 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   0 out of   4 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#security-policy"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU Lesser General Public License v3.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 25.7.0 not signed: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/236661103","Warn: release artifact 25.6.0 not signed: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/227265678","Warn: release artifact 25.5.0 not signed: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/224026344","Warn: release artifact 25.4.0 not signed: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/223697745","Warn: release artifact 1.24.0 not signed: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/223460215","Warn: release artifact 25.7.0 does not have provenance: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/236661103","Warn: release artifact 25.6.0 does not have provenance: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/227265678","Warn: release artifact 25.5.0 does not have provenance: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/224026344","Warn: release artifact 25.4.0 does not have provenance: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/223697745","Warn: release artifact 1.24.0 does not have provenance: https://api.github.com/repos/mc1arke/sonarqube-community-branch-plugin/releases/223460215"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#signed-releases"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 16 commits out of 17 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-14T14:29:31.850Z","repository_id":37442870,"created_at":"2025-08-14T14:29:31.850Z","updated_at":"2025-08-14T14:29:31.850Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29946463,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-28T17:57:52.716Z","status":"ssl_error","status_checked_at":"2026-02-28T17:57:31.974Z","response_time":90,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["sonarqube","sonarqube-analysis","sonarqube-plugin","sonarqube-scanner","sonarqube-server"],"created_at":"2024-10-29T10:42:34.852Z","updated_at":"2026-02-28T18:01:06.306Z","avatar_url":"https://github.com/mc1arke.png","language":"Java","funding_links":["https://github.com/sponsors/mc1arke"],"categories":["Java","Secure Programming"],"sub_categories":["SAST"],"readme":"[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=mc1arke_sonarqube-community-branch-plugin\u0026metric=alert_status)](https://sonarcloud.io/dashboard?id=mc1arke_sonarqube-community-branch-plugin)\n[![Build Status](https://img.shields.io/github/actions/workflow/status/mc1arke/sonarqube-community-branch-plugin/.github/workflows/build.yml?branch=master\u0026logo=github)](https://github.com/mc1arke/sonarqube-community-branch-plugin?workflow=build)\n\n# SonarQube Community Branch Plugin\n\nA plugin for SonarQube to allow branch analysis and pull request decoration in the\nCommunity version.\n\n# Support\n\nThis plugin is not maintained or supported by SonarSource and has no official upgrade path for migrating from the\nSonarQube Community Edition to any of the Commercial Editions (Developer, Enterprise, or Data Center Edition). Support\nfor any problems is only available through issues on the Github repository or through alternative channels (e.g.\nStackOverflow) and any attempt to request support for this plugin directly from SonarSource or an affiliated channel (\ne.g. Sonar Community forum) is likely to result in your request being closed or ignored.\n\nIf you plan on migrating your SonarQube data to a commercial edition after using this plugin then please be aware that\nthis may result in some or all of your data being lost due to this compatibility of this plugin and the official\nSonarQube branch features being untested.\n\n# Compatibility\n\nThe plugin major and minor versions match the SonarQube version it is compatible with,\ne.g. `25.4.0` of the plugin is compatible with SonarQube 25.4.x. Any older plugin\nversion is not guaranteed to work, nor are newer SonarQube versions guaranteed to work\nwith previous plugin versions.\n\n# Features\n\nThe plugin is intended to support the\nfeatures and parameters from the SonarQube [branch](https://docs.sonarsource.com/sonarqube-server/latest/analyzing-source-code/branch-analysis/introduction/)\nand [pull request](https://docs.sonarsource.com/sonarqube-server/latest/analyzing-source-code/pull-request-analysis/introduction/) documentation.\n\n# Installation\n\n## Manual Install\n\n**Please ensure you follow the installation instructions for the version of the plugin you're installing by looking at\nthe README on the relevant release tag.**\n\nEither build the project\nor [download a compatible release version of the plugin JAR and associated sonarqube-webapp.zip](https://github.com/mc1arke/sonarqube-community-branch-plugin/releases)\n.\n\n1. Copy the plugin JAR file to the `extensions/plugins/` directory of your SonarQube instance\n2. Add `-javaagent:./extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=web` to\n   the `sonar.web.javaAdditionalOpts` property in your SonarQube installation's `conf/sonar.properties` file,\n   e.g. `sonar.web.javaAdditionalOpts=-javaagent:./extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=web`\n   where ${version} is the version of the plugin being worked with. e.g `1.8.0`\n3. Add `-javaagent:./extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=ce` to\n   the `sonar.ce.javaAdditionalOpts` property in your SonarQube installation's `conf/sonar.properties` file,\n   e.g. `sonar.ce.javaAdditionalOpts=-javaagent:./extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=ce`\n4. Replace the contents of the `web` directory in your SonarQube installation with the contents of the sonarqube-webapp zip archive\n5. Start SonarQube, and accept the warning about using third-party plugins\n\n## Docker\n\nThe plugin is distributed in\nthe [mc1arke/sonarqube-with-community-branch-plugin](https://hub.docker.com/r/mc1arke/sonarqube-with-community-branch-plugin)\nDocker image, with the image versions matching the up-stream SonarQube image version.\n\n**Note:** If you're setting the `SONAR_WEB_JAVAADDITIONALOPTS` or `SONAR_CE_JAVAADDITIONALOPTS` environment variables in\nyour container launch then you'll need to add the `javaagent` configuration to your overrides to match what's in the\nprovided Dockerfile.\n\n## Docker Compose\n\nA `docker-compose.yml` file is provided.\nIt uses the env variables available in `.env`.\n\nTo use it, clone the repository, create a `.env` with `SONARQUBE_VERSION` defined, and execute `docker compose up`. Note that you need to have `docker compose` installed in your system and added to your PATH.\n\n## Kubernetes with the Official Helm Chart\n\nWhen using the\n[SonarQube official Helm Chart](https://github.com/SonarSource/helm-chart-sonarqube/tree/master/charts/sonarqube),\nadd the following settings to your helm values, where `${version}` should be replaced with the plugin\nversion (e.g. `25.4.0`).\n\n```yaml\ncommunity:\n  enabled: true\n\nplugins:\n  install:\n    - https://github.com/mc1arke/sonarqube-community-branch-plugin/releases/download/${version}/sonarqube-community-branch-plugin-${version}.jar\nsonarProperties:\n  sonar.web.javaAdditionalOpts: \"-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=web\"\n  sonar.ce.javaAdditionalOpts: \"-javaagent:/opt/sonarqube/extensions/plugins/sonarqube-community-branch-plugin-${version}.jar=ce\"\n\nextraVolumes:\n  - name: webapp\n    emptyDir:\n      sizeLimit: 50Mi\nextraVolumeMounts:\n  - name: webapp\n    mountPath: /opt/sonarqube/web\nextraInitContainers:\n  - name: download-webapp\n    image: busybox:1.37\n    volumeMounts:\n      - name: webapp\n        mountPath: /web\n    command:\n      - sh\n      - -c\n      - wget -O /tmp/sonarqube-webapp.zip https://github.com/mc1arke/sonarqube-community-branch-plugin/releases/download/${version}/sonarqube-webapp.zip \u0026\u0026\n        unzip -o /tmp/sonarqube-webapp.zip -d /web \u0026\u0026\n        chmod -R 755 /web \u0026\u0026\n        chown -R 1000:0 /web \u0026\u0026\n        rm -f /tmp/sonarqube-webapp.zip\n```\n\n# Configuration\n\n## Global configuration\n\nMake sure `sonar.core.serverBaseURL` in SonarQube [/admin/settings](http://localhost:9000/admin/settings) is properly\nset in order to for the links in the comment to work.\n\nSet all other properties that you can define globally for all of your projects.\n\n## How to decorate a Pull Request\n\nIn order to decorate your Pull Request's source branch, you need to analyze your target branch first.\n\n### Run analysis of branches\n\nIf the scan is being run from a CI supporting auto-configuration then the scanner can be launched without any branch\nparameters. Otherwise, the analysis needs the following setting:\n`sonar.branch.name = branch_name (e.g master)`\n\n### Run analysis of the PR branch\n\nCarefully read the official SonarQube guide\nfor [pull request decoration](https://docs.sonarqube.org/latest/analysis/pull-request/)\n\nIn there you'll find the following properties that need to be set, unless your CI support auto-configuration.\n\n```\nsonar.pullrequest.key = pull_request_id (e.g. 100)\nsonar.pullrequest.branch = source_branch_name (e.g feature/TICKET-123)\nsonar.pullrequest.base = target_branch_name (e.g master)\n```\n\n:warning: There must not be any `sonar.branch` properties like `sonar.branch.name` arguments set when you analyze a\npull-request. These properties indicate to sonar that a branch is being analyzed rather than a pull-request so no\npull-request decoration will be executed.\n\nIf you are scanning a GitHub pull request, you will also need to set the `sonar.scm.revision` argument.\n\nFor example, using the official [SonarQube Scan](https://github.com/marketplace/actions/official-sonarqube-scan)\non GitHub Actions:\n\n```yaml\n- name: SonarQube Scan\n  uses: sonarsource/sonarqube-scan-action@\u003caction version\u003e\n  with:\n    args: \u003e\n      -Dsonar.scm.revision=${{ github.event.pull_request.head.sha }}\n  env:\n    SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}\n    SONAR_HOST_URL: ${{ vars.SONAR_HOST_URL }}\n```\n\n## Serving images for PR decoration\n\nBy default, images for PR decoration are served as static resources on the SonarQube server as a part of Community\nBranch Plugin.\n\nIf you use a SonarQube server behind a firewall and/or PR service (Github, Gitlab etc.) doesn't have access to SonarQube\nserver, you should change `Images base URL` property in `General \u003e Pull Request` settings.\n\nAnyone needing to set this value can use the\nURL `https://raw.githubusercontent.com/mc1arke/sonarqube-community-branch-plugin/master/src/main/resources/static`, or\ndownload the files from this location and host them themself.\n\n# Building the plugin from source\n\nRun the following command to build and run a container with the plugin and modified frontend code:\n\n```bash\ndocker compose up --build\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmc1arke%2Fsonarqube-community-branch-plugin","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmc1arke%2Fsonarqube-community-branch-plugin","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmc1arke%2Fsonarqube-community-branch-plugin/lists"}