This project is analysed on SonarQube!
It is very easy to analyze a C, C++ and Objective-C project with SonarQube on Azure DevOps:
-
Create a
sonar-project.properties
file to store your configuration -
Install SonarQube extension for your organization:
-
Open Organization settings (in the bottom left corner of organization view)
-
Open "Extensions" page (in the General category)
-
Press "Browse marketplace" and find "SonarQube"
-
Select your organization and click "Install"
-
-
Add the SonarQube connection to your project:
-
Open Project settings (in the bottom left corner)
-
Open "Service connections" page (in the Pipelines category)
-
Press "New connection" and select "SonarQube""
-
Fill in the server URL (e.g.: https://example.com:9000) and the authentication token
-
Name your connection
SonarQube
(to reference it later inazure-pipelines.yml
)
-
-
In your
azure-pipelines.yml
file:-
Add the
SonarQubePrepare
task and configure it:-
Specify the
SonarQube Service Endpoint
asSonarQube
- the connection you created earlier -
Choose "Use standalone scanner" (
scannerMode: 'CLI'
) -
Choose "Manually provide configuration"
-
Specify the "Project Key" and the "Sources directory root"
-
In "Additional Properties" in the "Advanced" section, add
-
the property
sonar.cfamily.compile-commands
with, as its value,bw-output/compile_commands.json
, if you are using SonarQube version 10.6 or later -
the property
sonar.cfamily.build-wrapper-output
, with valuebw-output
, if you are using SonarQube version 10.5 or earlier, as build-wrapper did not generate acompile_commands.json
file before SonarQube 10.6
Noting that
bw-output
is the directory passed to build wrapper as--out-dir
(see below) -
-
-
Add a task to download the Build Wrapper
-
Wrap your compilation with the Build Wrapper, specifying the same output directory used in "Additional Properties"
-
Add the
SonarQubeAnalyze
task
-
You can take a look at the sonar-project.properties and azure-pipelines.yml to see it in practice.
The following warning may appear during invocation of /build-wrapper-macosx-x86
. To best of our knowledge does not affect the result of the analysis:
dyld: warning: could not load inserted library '/Users/runner/.sonar/build-wrapper-macosx-x86/libinterceptor.dylib' into hardened process because no suitable image found. Did find: /Users/runner/.sonar/build-wrapper-macosx-x86/libinterceptor.dylib: code signature in (/Users/runner/.sonar/build-wrapper-macosx-x86/libinterceptor.dylib) not valid for use in process using Library Validation: mapped file has no cdhash, completely unsigned? Code has to be at least ad-hoc signed.
For details please reffer to following ticket and community thread.
A build of the code repository on a macOS using XCode build system.
To build the code run from the repository root directory:
xcodebuild
An example of a flawed C++ code. The code repository is meant to be compiled with different build systems using different CI pipelines on Linux, macOS, and Windows.
The code repository is forked into other repositories in this collection to add a specific build system, platform, and CI. The downstream repositories are analyzed either with SonarQube or SonarCloud.
You can find examples for:
Using the following build systems:
Running on the following CI services:
-
Additionally, generic examples demonstrate integration with other CIs and manual-configuration examples should help you if you are running locally.
Configured for analysis on:
You can find also a few examples demonstrating:
See examples-structure.adoc for a description of the structure of this GitHub organization and the relations between its different repositories.