From 63f856ecf59a8a7a7c8d2e2d82fd8a0e119d47ba Mon Sep 17 00:00:00 2001 From: Travis Date: Tue, 15 Sep 2026 16:44:57 +0000 Subject: [PATCH] Build: add a project-specific SonarQube scan Configures the org.sonarqube plugin so each spring-* sub-module is analyzed as its own SonarQube project keyed org.springframework:, rather than as a single aggregated scan of the whole build. Each module's configuration lives in its own build file so it can be reviewed and merged independently. Server URL and token are read from the SONAR_HOST_URL and SONAR_TOKEN environment variables rather than being hardcoded. --- spring-webmvc/spring-webmvc.gradle | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/spring-webmvc/spring-webmvc.gradle b/spring-webmvc/spring-webmvc.gradle index 194278ad7c07..3e4d27ad63e5 100644 --- a/spring-webmvc/spring-webmvc.gradle +++ b/spring-webmvc/spring-webmvc.gradle @@ -1,3 +1,7 @@ +plugins { + id 'org.sonarqube' version '7.4.0.8496' +} + description = "Spring Web MVC" apply plugin: "kotlin" @@ -82,3 +86,13 @@ dependencies { testRuntimeOnly("org.python:jython-standalone") testRuntimeOnly("org.webjars:momentjs:2.29.4") } + +// This module is analyzed as its own SonarQube project. +sonar { + properties { + property 'sonar.projectKey', 'org.springframework:spring-webmvc' + property 'sonar.projectName', 'Spring Web MVC' + property 'sonar.projectVersion', project.version + property 'sonar.sourceEncoding', 'UTF-8' + } +}