The SonarQube analysis has to be run on the outside of Bitbucket. The most common scenario is an integration of the analysis into the build pipeline. A typical sonar analysis has the following steps:
New code changes pushed to a branch, or a pull request that has been created in Bitbucket
The build pipeline is triggered and informed of the new changes
A build is run, which triggers the Sonar analysis and executes the SonarScanner or one of its build system dependent alternatives.
The results of the analysis are sent to the SonarQube application
The SonarQube application informs Sonar for Bitbucket plugin over a webhook that a new analysis is complete. Sonar for Bitbucket annotates the pull request with the issues found in the analysis.
Whichever external system you use to execute the Sonar scan, you need to run it with the correct parameters for your SonarQube application. Use the analysis parameter matrix below to find yours.
Analysis Parameter Matrix
The table shows the minimally necessary parameters to get Sonar for Bitbucket to work with SonarScanner. Look at the SonarQube documentation for additional parameters or different scanning methods.
Developer Edition or higher | Community Edition | SonarCloud | |
---|---|---|---|
sonar-scanner \ -Dsonar.projectKey=<SONAR_PROJECT_KEY> \ -Dsonar.host.url=<SONAR_SERVER_URL> | sonar-scanner \ -Dsonar.projectKey=<SONAR_PROJECT_KEY_PREFIX:BRANCH_NAME> \ -Dsonar.host.url=<SONAR_SERVER_URL> SonarQube versions 7.9.x and 8.x only allow certain characters Use the same character as configured in the SonarQube server configuration under ‘Branch renaming for Sonar Project Keys’
| sonar-scanner \ -Dsonar.projectKey=<SONAR_PROJECT_KEY_PREFIX:BRANCH_NAME> \ -Dsonar.host.url=https://sonarcloud.io \ -Dsonar.organization=<SONAR_CLOUD_ORGANIZATION> | |
Branch Analysis | -Dsonar.branch.name=<branch_name> | Not needed with correct sonar project key | See Developer Edition or higher |
Pull Request Analysis | -Dsonar.pullrequests.key=<pull request identifier from VCS> -Dsonar.pullrequest.branch=<source branch name of pull request> -Dsonar.pullrequest.base=<destination branch name of pull request> | Take the source branch name of pull requests for | See Developer Edition or higher |
Only SonarQube 7.7 | -Dsonar.analysis.scmRevision=COMMIT_ID | -Dsonar.analysis.scmRevision=COMMIT_ID | Not needed |
Build Systems
Bamboo
We provide a first class integration for Bamboo with our Sonar for Bamboo plugin. See our dedicated wiki page for more information.
Jenkins
Use the Bitbucket Webhook to Jenkins plugin to notify Jenkins about new code changes. See these instructions on how to set it up. It is important to enable the setting "Omit SHA1 Hash Code" in the repository settings of the plug-in (see this issue on Github for more details):
Follow the instructions on the Sonar Scanner for Jenkins Wiki to set up the SonarScanner configuration.
The Jenkins Git plugin includes the
origin/
prefix in branch names, which has to be removed. Use a Jenkins freestyle jobecho SONAR_BRANCH=$(printf '%s' $GIT_BRANCH | cut -d'/' -f 2-) > sonar-branch
SonarQube versions 7.9.x and 8.x need to replace illegal branch characters. Use command:
echo SONAR_BRANCH=$(printf '%s' $GIT_BRANCH | cut -d'/' -f 2- | sed s/[^0-9a-zA-Z:_.\-]/'<YOUR_CONFIGURED_CHAR>'/g) > sonar-branch
Problems During Setup
We at Mibex Software are happy to help you in our support desk or at support@mibexsoftware.com