ActionRank

SonarQube Cloud Scan

Abandoned

SonarSource/sonarcloud-github-action · LGPL-3.0 · archived

Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.

607 starsLast commit 1 year agoLatest v5.0.0
F
32
/ 100
Security 59Maintenance 0Popularity 57Reliability 0

Security signals

OpenSSF Scorecard4.8 / 10
SECURITY.md presentYes
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: SonarSource/sonarcloud-github-action@ffc3010689be73b8e5ae0c57ce35968afd7909e8 # v5.0.0

Mutable tags like v5.0.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: SonarSource/sonarcloud-github-action@ffc3010689be73b8e5ae0c57ce35968afd7909e8 # v5.0.0

Score breakdown

Security (35%)59
Popularity (20%)57
Maintenance (30%)0
Reliability (15%)0

Add this badge to your README

ActionRank grade badge for SonarQube Cloud Scan
Markdown
[![ActionRank](https://actionrank.dev/api/badge/sonarsource-sonarcloud-github-action)](https://actionrank.dev/actions/sonarsource-sonarcloud-github-action)
HTML version
HTML
<a href="https://actionrank.dev/actions/sonarsource-sonarcloud-github-action"><img src="https://actionrank.dev/api/badge/sonarsource-sonarcloud-github-action" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for SonarQube Cloud Scan

We'll email you only if SonarQube Cloud Scan becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address