SQSCANGHA-134 Upgrade the libraries to latest version #266
qa-main.yml
on: pull_request
'scannerVersion' input
6s
'scannerBinariesUrl' input with invalid URL
33s
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
36s
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
53s
Don't fail on Gradle project
6s
Don't fail on Kotlin Gradle project
7s
Don't fail on Maven project
6s
runAnalysisTest
1m 41s
runAnalysisWithCacheTest
1m 41s
curl performs redirect when scannerBinariesUrl returns 3xx
36s
Analysis takes into account 'SONAR_ROOT_CERT'
1m 37s
truststore.p12 is updated when present
14s
'scannerVersion' input validation
4s
Matrix: 'args' input with command injection will fail
Matrix: 'args' input
Matrix: 'args' input with backticks injection does not execute command
Matrix: 'args' input with dollar command injection does not execute command
Matrix: No inputs
Matrix: 'args' input with other command injection variants does not execute command
Matrix: 'SONARCLOUD_URL' is used
Matrix: 'projectBaseDir' input
Matrix: 'RUNNER_DEBUG' is used
Matrix: 'SONAR_ROOT_CERT' is converted to truststore
Annotations
12 errors and 48 warnings
|
'args' input with command injection will fail (macos-latest, -Dsonar.someArg=aValue && echo "Inje...
Action failed: The process '/Users/runner/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/macosx-aarch64/bin/sonar-scanner' failed with exit code 1
|
|
'args' input with command injection will fail (macos-latest, -Dsonar.someArg="value\"; whoami; ec...
Action failed: The process '/Users/runner/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/macosx-aarch64/bin/sonar-scanner' failed with exit code 1
|
|
'scannerVersion' input validation
Sanity checks failed: Invalid scannerVersion format. Expected format: x.y.z.w (e.g., 7.1.0.4889)
|
|
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
Action failed: Invalid URL
|
|
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg="value\"; ...
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
|
|
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg=aValue && ...
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
|
|
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
Action failed: Invalid URL
|
|
'scannerBinariesUrl' input with invalid URL
Action failed: getaddrinfo EAI_AGAIN invalid_uri
|
|
Analysis takes into account 'SONAR_ROOT_CERT'
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/bin/sonar-scanner' failed with exit code 1
|
|
Analysis takes into account 'SONAR_ROOT_CERT'
Action failed: The process '/opt/hostedtoolcache/sonar-scanner-cli/8.0.1.6346/linux-x64/jre/bin/java' failed with exit code 1
|
|
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg="value\";...
Action failed: The process 'C:\hostedtoolcache\windows\sonar-scanner-cli\8.0.1.6346\windows-x64\bin\sonar-scanner.bat' failed with exit code 1
|
|
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg=aValue &&...
Action failed: The process 'C:\hostedtoolcache\windows\sonar-scanner-cli\8.0.1.6346\windows-x64\bin\sonar-scanner.bat' failed with exit code 1
|
|
'args' input with dollar command injection does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
No inputs (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'RUNNER_DEBUG' is used (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with backticks injection does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with dollar command injection does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'projectBaseDir' input (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (macos-latest, -Dsonar.someArg=aValue && echo "Inje...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with other command injection variants does not execute command (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (macos-latest, -Dsonar.someArg="value\"; whoami; ec...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'SONAR_ROOT_CERT' is converted to truststore (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
No inputs (macos-latest)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Don't fail on Kotlin Gradle project
Gradle project detected. Sonar recommends using the SonarQube plugin for Gradle during the build process instead of using this GitHub Action to get more accurate results.
|
|
Don't fail on Kotlin Gradle project
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'RUNNER_DEBUG' is used (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'SONAR_ROOT_CERT' is converted to truststore (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with other command injection variants does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with backticks injection does not execute command (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'scannerBinariesUrl' is escaped with curl so special chars are not injected in the download command
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'scannerVersion' input
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with backticks injection does not execute command (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Don't fail on Maven project
Maven project detected. Sonar recommends running the 'org.sonarsource.scanner.maven:sonar-maven-plugin:sonar' goal during the build process instead of using this GitHub Action to get more accurate results.
|
|
Don't fail on Maven project
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Don't fail on Gradle project
Gradle project detected. Sonar recommends using the SonarQube plugin for Gradle during the build process instead of using this GitHub Action to get more accurate results.
|
|
Don't fail on Gradle project
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg="value\"; ...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
truststore.p12 is updated when present
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'projectBaseDir' input (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (github-ubuntu-latest-s, -Dsonar.someArg=aValue && ...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'SONAR_ROOT_CERT' is converted to truststore (github-ubuntu-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'scannerBinariesUrl' is escaped with wget so special chars are not injected in the download command
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'scannerBinariesUrl' input with invalid URL
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
curl performs redirect when scannerBinariesUrl returns 3xx
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
Analysis takes into account 'SONAR_ROOT_CERT'
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
runAnalysisTest
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
runAnalysisWithCacheTest
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg="value\";...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with command injection will fail (github-windows-latest-s, -Dsonar.someArg=aValue &&...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'RUNNER_DEBUG' is used (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with dollar command injection does not execute command (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input with other command injection variants does not execute command (github-windows-lates...
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'args' input (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|
|
'projectBaseDir' input (github-windows-latest-s)
Running this GitHub Action without SONAR_TOKEN is not recommended
|