Skip to content

BUILD-10861 Dependabot 5-day cooldown + internal excludes (#225) #263

BUILD-10861 Dependabot 5-day cooldown + internal excludes (#225)

BUILD-10861 Dependabot 5-day cooldown + internal excludes (#225) #263

Triggered via push April 2, 2026 13:07
Status Success
Total duration 3m 58s
Artifacts

qa-main.yml

on: push
'scannerVersion' input
9s
'scannerVersion' input
'scannerBinariesUrl' input with invalid URL
29s
'scannerBinariesUrl' input with invalid URL
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
26s
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
56s
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
Don't fail on Gradle project
7s
Don't fail on Gradle project
Don't fail on Kotlin Gradle project
7s
Don't fail on Kotlin Gradle project
Don't fail on Maven project
10s
Don't fail on Maven project
runAnalysisTest
1m 48s
runAnalysisTest
runAnalysisWithCacheTest
1m 30s
runAnalysisWithCacheTest
curl performs redirect when scannerBinariesUrl returns 3xx
44s
curl performs redirect when scannerBinariesUrl returns 3xx
Analysis takes into account 'SONAR_ROOT_CERT'
1m 27s
Analysis takes into account 'SONAR_ROOT_CERT'
truststore.p12 is updated when present
18s
truststore.p12 is updated when present
'scannerVersion' input validation
3s
'scannerVersion' input validation
Matrix: 'args' input with command injection will fail
Matrix: 'args' input
Matrix: 'args' input with backticks injection does not execute command
Matrix: 'args' input with dollar command injection does not execute command
Matrix: No inputs
Matrix: 'args' input with other command injection variants does not execute command
Matrix: 'SONARCLOUD_URL' is used
Matrix: 'projectBaseDir' input
Matrix: 'RUNNER_DEBUG' is used
Matrix: 'SONAR_ROOT_CERT' is converted to truststore
Fit to window
Zoom out
Zoom in

Annotations

12 errors and 48 warnings
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg=aValue && ...
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
'args' input with command injection will fail (macos-latest, -Dsonar.someArg=aValue && echo "Inje...
Action failed: The process '/Users/runner/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/macosx-aarch64/bin/sonar-scanner' failed with exit code 1
'args' input with command injection will fail (macos-latest, -Dsonar.someArg="value\"; whoami; ec...
Action failed: The process '/Users/runner/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/macosx-aarch64/bin/sonar-scanner' failed with exit code 1
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg="value\"; ...
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
'scannerVersion' input validation
Sanity checks failed: Invalid scannerVersion format. Expected format: x.y.z.w (e.g., 7.1.0.4889)
'scannerBinariesUrl' input with invalid URL
Action failed: getaddrinfo EAI_AGAIN invalid_uri
Analysis takes into account 'SONAR_ROOT_CERT'
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
Analysis takes into account 'SONAR_ROOT_CERT'
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/jre/bin/java' failed with exit code 1
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg=aValue &&...
Action failed: The process 'C:\hostedtoolcache\windows\sonar-scanner-cli\8.0.1.6346\windows-x64\bin\sonar-scanner.bat' failed with exit code 1
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg="value\";...
Action failed: The process 'C:\hostedtoolcache\windows\sonar-scanner-cli\8.0.1.6346\windows-x64\bin\sonar-scanner.bat' failed with exit code 1
'RUNNER_DEBUG' is used (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg=aValue && ...
Running this GitHub Action without SONAR_TOKEN is not recommended
Don't fail on Gradle project
Gradle project detected. Sonar recommends using the SonarQube plugin for Gradle during the build process instead of using this GitHub Action to get more accurate results.
Don't fail on Gradle project
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (macos-latest, -Dsonar.someArg=aValue && echo "Inje...
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (macos-latest, -Dsonar.someArg="value\"; whoami; ec...
Running this GitHub Action without SONAR_TOKEN is not recommended
No inputs (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'projectBaseDir' input (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with backticks injection does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'RUNNER_DEBUG' is used (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with dollar command injection does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with other command injection variants does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'SONAR_ROOT_CERT' is converted to truststore (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
'scannerVersion' input
Running this GitHub Action without SONAR_TOKEN is not recommended
'projectBaseDir' input (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg="value\"; ...
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with dollar command injection does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with other command injection variants does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with backticks injection does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'SONAR_ROOT_CERT' is converted to truststore (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
Don't fail on Kotlin Gradle project
Gradle project detected. Sonar recommends using the SonarQube plugin for Gradle during the build process instead of using this GitHub Action to get more accurate results.
Don't fail on Kotlin Gradle project
Running this GitHub Action without SONAR_TOKEN is not recommended
No inputs (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
Don't fail on Maven project
Maven project detected. Sonar recommends running the 'org.sonarsource.scanner.maven:sonar-maven-plugin:sonar' goal during the build process instead of using this GitHub Action to get more accurate results.
Don't fail on Maven project
Running this GitHub Action without SONAR_TOKEN is not recommended
'scannerBinariesUrl' input with invalid URL
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
Running this GitHub Action without SONAR_TOKEN is not recommended
curl performs redirect when scannerBinariesUrl returns 3xx
Running this GitHub Action without SONAR_TOKEN is not recommended
runAnalysisWithCacheTest
Running this GitHub Action without SONAR_TOKEN is not recommended
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with dollar command injection does not execute command (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg=aValue &&...
Running this GitHub Action without SONAR_TOKEN is not recommended
runAnalysisTest
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with other command injection variants does not execute command (github-windows-lates...
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg="value\";...
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input with backticks injection does not execute command (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'args' input (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'SONAR_ROOT_CERT' is converted to truststore (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'RUNNER_DEBUG' is used (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
'projectBaseDir' input (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended