Skip to content

ci(release): mark the generator's tag reference as deliberate for SonarCloud - #104

Merged
mescon merged 1 commit into
masterfrom
ci/sonar-generator-tag
Sep 15, 2026
Merged

mescon merged 1 commit into
masterfrom
ci/sonar-generator-tag

Conversation

@mescon

@mescon mescon commented Sep 15, 2026

Copy link
Copy Markdown
Owner

SonarCloud rule S7637 (pin by hash) fails the quality gate on the SLSA generator reference, which must stay a tag for slsa-verifier. This adds the NOSONAR marker with the reason on that line. The SonarCloud check on this PR shows whether the analyzer honours it for workflow files.

…arCloud

SonarCloud's pin-by-hash rule fails the quality gate on the SLSA
generator line. The generator has to be referenced by tag, or
slsa-verifier cannot verify its ref, so the line carries the marker
that tells the rule the choice is deliberate, with the reason.
@mescon
mescon enabled auto-merge September 15, 2026 10:31
@sonarqubecloud

Copy link
Copy Markdown

@mescon
mescon merged commit 37a2249 into master Sep 15, 2026
17 checks passed
@mescon
mescon deleted the ci/sonar-generator-tag branch September 22, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant