ActionRank

SonarQube Cloud Scan

Abandoned

SonarSource/sonarcloud-github-action · LGPL-3.0 · archived

Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.

607 starsLast commit 11 months agoLatest v5.0.0
F
32
/ 100
Security 59Maintenance 0Popularity 57Reliability 0

Security signals

OpenSSF Scorecard4.9 / 10
SECURITY.md presentYes
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: SonarSource/sonarcloud-github-action@ffc3010689be73b8e5ae0c57ce35968afd7909e8 # v5.0.0

Mutable tags like v5.0.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: SonarSource/sonarcloud-github-action@ffc3010689be73b8e5ae0c57ce35968afd7909e8 # v5.0.0

Score breakdown

Security (35%)59
Popularity (20%)57
Maintenance (30%)0
Reliability (15%)0