# Scan configuration, kept here rather than as inline -D arguments in # .gitea/workflows/sonarqube.yml so that a local scan and a CI scan analyse the # same thing. Only the host URL and token stay in CI secrets. sonar.projectKey=redefined-designs sonar.projectName=redefined-designs sonar.sources=backend/src,frontend/src sonar.exclusions=**/node_modules/**,**/dist/** sonar.sourceEncoding=UTF-8 # The new-code period. Without this the gate silently grades the entire codebase # rather than what changed: the server's period is PREVIOUS_VERSION, and with no # version ever declared there is no previous version to diff against, so every # line counts as new. The symptom is new_lines (9460) exceeding total ncloc # (5496) and new_coverage tracking overall coverage to within two points, which # looks like a working gate right up until you check. See #79. # # PREVIOUS_VERSION baselines at the first analysis carrying a given version, so # "new code" here means everything since this number last changed. Bump it when # a release is cut and the baseline moves with it; leave it alone and the window # simply keeps widening, which is the honest behaviour rather than a silent one. # # Kept in step with the version in backend/package.json and frontend/package.json # by hand. Nothing enforces that, so change all three together. sonar.projectVersion=1.0.0 # Without this the analyser auto-discovers frontend/tsconfig.json, chokes on its # "moduleResolution": "bundler" — unrecognised by the TypeScript bundled with # SonarQube 9.9 — and silently drops all 34 frontend files while still exiting # EXECUTION SUCCESS. See #67. tsconfig.sonar.json is an analysis-only mirror; # both it and this line go away once the server can parse "bundler". sonar.typescript.tsconfigPaths=backend/tsconfig.json,frontend/tsconfig.sonar.json # Test sources, so they are analysed under the test rule set rather than as # production code — or, as before, not at all. sonar.tests=backend/tests,frontend/tests # Coverage. Three reports because the suites cover genuinely different things and # jest would otherwise overwrite one with the other: the unit suite alone reports # ~11% because everything in src/routes is exercised by the integration suite, # not by it. SonarQube merges them, so a line covered by any suite counts. # # Read the frontend number with suspicion. It comes from Playwright through an # istanbul-instrumented dev server, and istanbul marks a line covered when the # browser ran it — a component renders during an end-to-end test and reports as # covered with nothing asserting anything about it. See #61's design doc. sonar.javascript.lcov.reportPaths=backend/coverage/unit/lcov.info,backend/coverage/integration/lcov.info,frontend/coverage/lcov.info