{"id":28495994,"url":"https://github.com/sonarsource/sonar-scanner-gradle","last_synced_at":"2026-02-23T17:27:55.390Z","repository":{"id":32440261,"uuid":"36018469","full_name":"SonarSource/sonar-scanner-gradle","owner":"SonarSource","description":"SonarQube Scanner for Gradle","archived":false,"fork":false,"pushed_at":"2025-06-24T08:06:37.000Z","size":1585,"stargazers_count":198,"open_issues_count":3,"forks_count":93,"subscribers_count":46,"default_branch":"master","last_synced_at":"2025-06-24T09:25:02.300Z","etag":null,"topics":["gradle-plugin"],"latest_commit_sha":null,"homepage":"https://redirect.sonarsource.com/doc/gradle.html","language":"Java","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"lgpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/SonarSource.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"contributing.md","funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2015-05-21T14:45:46.000Z","updated_at":"2025-06-24T08:06:40.000Z","dependencies_parsed_at":"2024-01-05T10:54:44.917Z","dependency_job_id":"ef09f2eb-2785-4843-81a7-c011ca0f00ba","html_url":"https://github.com/SonarSource/sonar-scanner-gradle","commit_stats":null,"previous_names":[],"tags_count":56,"template":false,"template_full_name":null,"purl":"pkg:github/SonarSource/sonar-scanner-gradle","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-gradle","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-gradle/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-gradle/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-gradle/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/SonarSource","download_url":"https://codeload.github.com/SonarSource/sonar-scanner-gradle/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-gradle/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":263165758,"owners_count":23424004,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["gradle-plugin"],"created_at":"2025-06-08T11:38:23.931Z","updated_at":"2026-02-23T17:27:55.384Z","avatar_url":"https://github.com/SonarSource.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"SonarScanner for Gradle\n============================\n\n[![Build Status](https://github.com/SonarSource/sonar-scanner-gradle/actions/workflows/build.yml/badge.svg?branch=master)](https://github.com/SonarSource/sonar-scanner-gradle/actions/workflows/build.yml) [![Quality Gate](https://next.sonarqube.com/sonarqube/api/project_badges/measure?project=org.sonarsource.scanner.gradle%3Asonarqube-gradle-plugin\u0026metric=alert_status)](https://next.sonarqube.com/sonarqube/dashboard?id=org.sonarsource.scanner.gradle%3Asonarqube-gradle-plugin)\n\nAbout Sonar\n-----------\n\nSonar's integrated code quality and code security solutions help developers deliver high-quality, efficient code standards that benefit the entire team or organization.\n\nUser documentation\n------------------\n\nhttps://redirect.sonarsource.com/doc/gradle.html\n\nHave Questions or Feedback?\n---------------------------\n\nFor support questions (\"How do I?\", \"I got this error, why?\", ...), please head to the [SonarSource forum](https://community.sonarsource.com/c/help). There are chances that a question similar to yours has already been answered. \n\nBe aware that this forum is a community, so the standard pleasantries (\"Hi\", \"Thanks\", ...) are expected. And if you don't get an answer to your thread, you should sit on your hands for at least three days before bumping it. Operators are not standing by. :-)\n\n\nContributing\n------------\n\nIf you would like to see a new feature, please create a new thread in the forum [\"Suggest new features\"](https://community.sonarsource.com/c/suggestions/features).\n\nPlease be aware that we are not actively looking for feature contributions. The truth is that it's extremely difficult for someone outside SonarSource to comply with our roadmap and expectations. Therefore, we typically only accept minor cosmetic changes and typo fixes.\n\nWith that in mind, if you would like to submit a code contribution, please create a pull request for this repository. Please explain your motives to contribute this change: what problem you are trying to fix, what improvement you are trying to make.\n\nMake sure that you follow our [code style](https://github.com/SonarSource/sonar-developer-toolset#code-style) and all tests are passing.\n\nThen, one of the members of our team will carefully review your pull request. You might be asked at this point for clarifications or your pull request might be rejected if we decide that it doesn't fit our roadmap and vision for the product.\n\nReporting Security Issues\n-------------------------\n\nA mature software vulnerability treatment process is a cornerstone of a robust information security management system. Contributions from the community play an important role in the evolution and security of our products, and in safeguarding the security and privacy of our users.\n\nIf you believe you have discovered a security vulnerability in Sonar's products, we encourage you to report it immediately.\n\nTo responsibly report a security issue, please email us at [security@sonarsource.com](mailto:security@sonarsource.com). Sonar’s security team will acknowledge your report, guide you through the next steps, or request additional information if necessary. Customers with a support contract can also report the vulnerability directly through the support channel.\n\nFor security vulnerabilities found in third-party libraries, please also contact the library's owner or maintainer directly.\n\n### Responsible Disclosure Policy\n\nFor more information about disclosing a security vulnerability to Sonar, please refer to our community post: [Responsible Vulnerability Disclosure](https://community.sonarsource.com/t/responsible-vulnerability-disclosure/9317).\n\n\nDeveloper documentation\n-----------------------\n\n### Building the project\nTo build the plugin and run the tests, you will need Java 11.\n```bash\n./gradlew clean build\n```\n\n#### Fix the error `* What went wrong: Dependency verification failed ... update the gradle/verification-metadata.xml file ...`\nYou need to update `gradle/verification-metadata.xml` and review it.\n```bash\n./gradlew --refresh-dependencies --info --stacktrace --write-verification-metadata sha256\ngit diff -- gradle/verification-metadata.xml\n```\nNote that the command above only updates the metadata for the dependencies used in the main task. There may be other dependencies used in other tasks, so you may want to run the command for other tasks as well, like `cyclonedxBom`:\n```bash\n./gradlew --refresh-dependencies --info --stacktrace --write-verification-metadata sha256 cyclonedxBom\n```\n\nOnce you have reviewed the changes, replace `origin=\"Generated by Gradle\"` with `origin=\"Verified\"` for the changes you accepted.\nAnd delete in the `verification-metadata.xml` the versions that we don't use anymore, because `--write-verification-metadata` don't remove unused dependencies.\nBut do not delete all unused versions for dependencies with a dynamic version set to `latest.release` (like `org.sonarsource.scanner.gradle:sonarqube-gradle-plugin`), \nbecause Gradle cache the version resolution for 24 hours, so for those dependencies, we also need to keep the before last version.\n\nWhen you update a dependency’s checksum in the gradle/verification-metadata.xml file, you validate the change by comparing the sha256 value from Artifactory with the one listed on another package repositories like maven central. \nFirst, identify the dependency updated in the file and copy its sha256 checksum. \nNext, search for the dependency on another package repositories. For instance on [Maven Central](https://central.sonatype.com), you can use the query `checksum:new-dependency-sha256` to find a specific dependency.\n\n### How the plugin works\nWhen the plugin is applied to a project, it will add to that project the Sonar task. It will also add to the project and all its subprojects the Sonar extension.\nFor multi-module projects, the plugin will only apply to the first project where it gets called. The goal is to allow the usage of `allprojects {}`, for example.\n\n**Sonar extension**\nThe `sonar` extension enables an easy configuration of a project with the Domain Specific Language.\n\n**Sonar task**\nThe Sonar task has the name `sonar`, so it can be executed by calling `./gradlew sonar`. It collects information from the project and all its subprojects, generating the properties for the analysis. Then, it runs the SonarScanner analysis using all those properties.\nThe task depends on all compile and test tasks of all projects (except for skipped projects).\nIf all projects are skipped (by adding `skipProject=true` to the sonar DSL), the analysis won't execute.\n\n\n### Using the plugin directly in a project (no need to build/install it in advance)\nA composite build can be used to substitute plugins with an included build.\n\nIn the target project, apply the `sonarqube` plugin:\n```\nplugins {\n  id 'org.sonarqube'\n}\n```\n\nRun with:\n```\n./gradlew sonar --include-build /path/to/sonar-scanner-gradle\n```\n\n### Debugging the plugin\nSee the previous point about including the plugin's build when building a target project.\nTo debug, simply add the parameter:\n```\n./gradlew sonar --include-build /path/to/sonar-scanner-gradle/build/classes/java/main/ -Dorg.gradle.debug=true\n```\n\nNow debug remotely by connecting to the port 5005.\n\n### Integration Tests\nBy default, Integration Tests are skipped during the build. To run them, you need to follow these steps:\n\n* Install the SNAPSHOT version of the root project in the local Maven repository.  \n* Import the `integationTests` project as a Maven project and ensure that Android SDK is set.  \n* Set `ANDROID_HOME` environment variable\n* Run the following command from the `integrationTests` project:\n    ```\n    mvn --errors --batch-mode clean verify\n    ```\n\n### Install a SNAPSHOT in the local Maven repository\n\n    ./gradlew publishToMavenLocal\n\n### Using the plugin SNAPSHOT previously installed in the local Maven repository\n\n```groovy\nbuildscript {\n    repositories { \n      mavenCentral()\n      mavenLocal()\n    }\n    dependencies { classpath 'org.sonarsource.scanner.gradle:sonarqube-gradle-plugin:\u003cTHE VERSION\u003e' }\n}\n\napply plugin: 'org.sonarqube'\n```\n\n### Release and deploy on Gradle plugin repository\n\nFollow the [Scanner for Gradle Release Process](https://xtranet-sonarsource.atlassian.net/wiki/spaces/SSG/pages/1181729/Scanner+for+Gradle+Release+Process)\n\nhttps://plugins.gradle.org/docs/publish-plugin\n\n    ./gradlew release\n\n\nLicense\n-------\n\nCopyright 2011-2025 SonarSource.\n\nLicensed under the [GNU Lesser General Public License, Version 3.0](http://www.gnu.org/licenses/lgpl.txt))\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsonarsource%2Fsonar-scanner-gradle","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsonarsource%2Fsonar-scanner-gradle","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsonarsource%2Fsonar-scanner-gradle/lists"}