Skip to content

Commit f251c39

Browse files
authored
fix(sonar): skip SonarCloud analysis on template repo (#80)
* fix(sonar): skip SonarCloud analysis on template repo Remove `.github/workflows/sonarcloud.yml` and root-level `sonar-project.properties`. As Jinja2 meta-code, this template body is not statically analyzable as Python, and the analysis was failing with a curl 403 from the SonarCloud quality-gate API (the project key was effectively unanalyzable: source paths like `{{cookiecutter.project_slug}}/` are literal text on the template-repo side and only become real directories in the rendered child project). Generated child projects continue to opt into their own SonarCloud analysis via the rendered `sonar-project.properties` and `sonarcloud.yml` workflow that ship inside the template's rendered output directory; that analysis is unaffected because it runs after cookiecutter has rendered the placeholders. Refs: Phase 3 Bucket E (CI Repair Sprint) * fix(docs): remove stale SonarCloud references after sonarcloud.yml deletion - README.md: drop SonarCloud badges; update setup section to reflect that the template repo is excluded from analysis (Jinja2 placeholders are not statically analyzable as Python) - CLAUDE.md: remove Template Repository subsection from SonarCloud section; retain Generated Projects subsection unchanged - ci.yml: drop SonarQube feature line from header; update Layer 3 description to Ruff/BasedPyright/Bandit to match actual toolchain - CHANGELOG.md: reorder [Unreleased] subsections to Added, Changed, Removed, Fixed per Keep a Changelog 1.1.0 spec (Removed was misplaced before Changed) - CONTRIBUTING.md: replace SonarCloud with qlty in automated reviewers list - .sonarlint/connectedMode.json: delete orphaned IDE config pointing to the now-deleted analysis project (caused SonarLint connection errors) - .secrets.baseline: add SHA-pin entries from .pre-commit-config.yaml that were false-positived as high-entropy secrets
1 parent 1fc987a commit f251c39

9 files changed

Lines changed: 102 additions & 232 deletions

File tree

.github/workflows/ci.yml

Lines changed: 6 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -3,15 +3,14 @@
33
#
44
# Features:
55
# - Standard quality checks (tests, linting, type checking)
6-
# - SonarQube quality gate enforcement
76
# - LLM anti-pattern detection
87
# - Assumption tag verification
98
# - Security scanning
109
#
1110
# Three-Layer Governance:
1211
# Layer 1: Production Runtime Risks (RAD tags)
1312
# Layer 2: LLM Development Debt (LLM tags)
14-
# Layer 3: Automated Code Quality (SonarQube)
13+
# Layer 3: Automated Code Quality (Ruff, BasedPyright, Bandit)
1514

1615
name: CI
1716

@@ -289,12 +288,11 @@ jobs:
289288
# ============================================================================
290289
# Job 3: Template Validation
291290
# ----------------------------------------------------------------------------
292-
# Note: SonarCloud scanning + quality gate are handled by the dedicated
293-
# sonarcloud.yml workflow (thin caller for the org reusable workflow at
294-
# ByronWilliamsCPA/.github/.github/workflows/python-sonarcloud.yml). A second
295-
# inline scan here caused two concurrent analyses for the same projectKey on
296-
# the same SHA, racing each other and producing the 'task not found' 404 from
297-
# sonarqube-quality-gate-action. See PR #69.
291+
# Note: SonarCloud analysis is intentionally NOT run on this template repo.
292+
# As meta-code (Jinja2 placeholders rendered at instantiation time), the
293+
# template body is not analyzable as plain Python. Generated child projects
294+
# opt into their own SonarCloud analysis via the rendered config that ships
295+
# inside the rendered template directory.
298296
# ============================================================================
299297
validate-template:
300298
name: Validate Cookiecutter Template
@@ -391,7 +389,6 @@ jobs:
391389
echo "All governance layers checked:" >> $GITHUB_STEP_SUMMARY
392390
echo "- ✅ Code Quality Checks" >> $GITHUB_STEP_SUMMARY
393391
echo "- ✅ LLM Governance Validation" >> $GITHUB_STEP_SUMMARY
394-
echo "- ✅ SonarCloud Analysis (via reusable workflow)" >> $GITHUB_STEP_SUMMARY
395392
echo "- ✅ Template Validation" >> $GITHUB_STEP_SUMMARY
396393
echo "" >> $GITHUB_STEP_SUMMARY
397394
echo "**Status: ${{ job.status }}**" >> $GITHUB_STEP_SUMMARY

.github/workflows/sonarcloud.yml

Lines changed: 0 additions & 44 deletions
This file was deleted.

.secrets.baseline

Lines changed: 74 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -133,13 +133,85 @@
133133
}
134134
],
135135
"results": {
136+
".pre-commit-config.yaml": [
137+
{
138+
"type": "Hex High Entropy String",
139+
"filename": ".pre-commit-config.yaml",
140+
"hashed_secret": "a6a0ba7241c2c0e8d2cb5980e4ebad99a38c4fc0",
141+
"is_verified": false,
142+
"line_number": 8
143+
},
144+
{
145+
"type": "Hex High Entropy String",
146+
"filename": ".pre-commit-config.yaml",
147+
"hashed_secret": "86242b7a7b67c1fd83514757a6b319602d648e94",
148+
"is_verified": false,
149+
"line_number": 28
150+
},
151+
{
152+
"type": "Hex High Entropy String",
153+
"filename": ".pre-commit-config.yaml",
154+
"hashed_secret": "32772e0f64714ee37c2509aa0a3ce917c5735cc6",
155+
"is_verified": false,
156+
"line_number": 43
157+
},
158+
{
159+
"type": "Hex High Entropy String",
160+
"filename": ".pre-commit-config.yaml",
161+
"hashed_secret": "ae599e2a19541d5442ce8d183650de9a35d2a78e",
162+
"is_verified": false,
163+
"line_number": 121
164+
},
165+
{
166+
"type": "Hex High Entropy String",
167+
"filename": ".pre-commit-config.yaml",
168+
"hashed_secret": "822f2dce9fa345f45a618777dd8de8f183ddfdef",
169+
"is_verified": false,
170+
"line_number": 139
171+
},
172+
{
173+
"type": "Hex High Entropy String",
174+
"filename": ".pre-commit-config.yaml",
175+
"hashed_secret": "5dc0a1cf00984ab9cbef49ac562ee6c48eea0674",
176+
"is_verified": false,
177+
"line_number": 147
178+
},
179+
{
180+
"type": "Hex High Entropy String",
181+
"filename": ".pre-commit-config.yaml",
182+
"hashed_secret": "beab4aad95563277a5a01fcf6e88a9a9d1bb6e9c",
183+
"is_verified": false,
184+
"line_number": 155
185+
},
186+
{
187+
"type": "Hex High Entropy String",
188+
"filename": ".pre-commit-config.yaml",
189+
"hashed_secret": "87f016410622dea3d25d65e5ef2e4fdad42fdb1d",
190+
"is_verified": false,
191+
"line_number": 163
192+
},
193+
{
194+
"type": "Hex High Entropy String",
195+
"filename": ".pre-commit-config.yaml",
196+
"hashed_secret": "d1d759c99cc716d64322cd46f7ed6c0ccd561e8d",
197+
"is_verified": false,
198+
"line_number": 170
199+
},
200+
{
201+
"type": "Hex High Entropy String",
202+
"filename": ".pre-commit-config.yaml",
203+
"hashed_secret": "6327141e0d23f165d2d00ce64fea19a4d95d625d",
204+
"is_verified": false,
205+
"line_number": 182
206+
}
207+
],
136208
"README.md": [
137209
{
138210
"type": "Secret Keyword",
139211
"filename": "README.md",
140212
"hashed_secret": "f7485c89e918d73cb3096af4ff0b916a27bf9a5d",
141213
"is_verified": false,
142-
"line_number": 327
214+
"line_number": 317
143215
}
144216
],
145217
"central-services/auth-service/README.md": [
@@ -234,5 +306,5 @@
234306
}
235307
]
236308
},
237-
"generated_at": "2026-05-20T04:32:31Z"
309+
"generated_at": "2026-05-28T01:59:41Z"
238310
}

.sonarlint/connectedMode.json

Lines changed: 0 additions & 5 deletions
This file was deleted.

CHANGELOG.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,16 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
114114
- Root `pyproject.toml`: added missing `A` (flake8-builtins) and `PT`
115115
(flake8-pytest-style) rule sets to `[tool.ruff.lint].select`
116116

117+
### Removed
118+
119+
- Root-level `sonar-project.properties` and `.github/workflows/sonarcloud.yml`
120+
caller workflow. SonarCloud analysis is intentionally skipped on this template
121+
repository: as Jinja2 meta-code, the template body is not statically
122+
analyzable as Python, and the analysis was failing with a `curl 403` from the
123+
SonarCloud quality-gate API. Generated child projects continue to opt into
124+
their own SonarCloud analysis via the rendered config that ships inside the
125+
template's rendered output directory.
126+
117127
### Fixed
118128

119129
- `setup_github_protection.py`: hardcoded context names replaced with Jinja2 conditionals

CLAUDE.md

Lines changed: 5 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -575,33 +575,11 @@ Templates can execute arbitrary code:
575575

576576
## SonarCloud Integration
577577

578-
Both the template repository and generated projects support SonarCloud for continuous code quality analysis.
579-
580-
### Template Repository
581-
582-
**Configuration**:
583-
584-
- **Organization**: `williaby`
585-
- **Project Key**: `ByronWilliamsCPA_cookiecutter-python-template`
586-
- **Analysis Method**: CI-Based (GitHub Actions)
587-
- **Workflow**: `.github/workflows/sonarcloud.yml`
588-
- **Configuration**: `sonar-project.properties`
589-
- **Dashboard**: <https://sonarcloud.io/project/overview?id=ByronWilliamsCPA_cookiecutter-python-template>
590-
591-
**What's Analyzed**:
592-
593-
- Hook files (`hooks/*.py`)
594-
- Template files (`{{cookiecutter.project_slug}}/`)
595-
- Code quality metrics (bugs, code smells, maintainability)
596-
- Security vulnerabilities and hotspots
597-
- Hook file test coverage (when tests exist)
598-
599-
**Quality Standards**:
600-
601-
- Quality gate must pass before merging PRs
602-
- Security rating must be A or B
603-
- Maintainability rating must be A or B
604-
- No critical or high-severity vulnerabilities
578+
Generated projects support SonarCloud for continuous code quality analysis. The template
579+
repository itself does not run SonarCloud: the Jinja2 template body is not statically
580+
analyzable as plain Python, and analysis was failing with a `curl 403` from the quality-gate
581+
API. Neither `sonar-project.properties` nor `.github/workflows/sonarcloud.yml` exist at the
582+
template repo root.
605583

606584
### Generated Projects
607585

CONTRIBUTING.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ git config --global commit.gpgsign true
9090
cd /tmp && rm -rf my_project
9191
```
9292
6. Open a pull request with a clear description of the change and why it is needed.
93-
7. Address any feedback from automated reviewers (CodeRabbit, SonarCloud) before
93+
7. Address any feedback from automated reviewers (CodeRabbit, qlty) before
9494
requesting human review.
9595

9696
## Coding Standards

README.md

Lines changed: 6 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,6 @@
11
# Cookiecutter Python Template
22

33
[![Validate Template](https://github.com/ByronWilliamsCPA/cookiecutter-python-template/actions/workflows/validate-template.yml/badge.svg)](https://github.com/ByronWilliamsCPA/cookiecutter-python-template/actions/workflows/validate-template.yml)
4-
[![SonarCloud](https://github.com/ByronWilliamsCPA/cookiecutter-python-template/actions/workflows/sonarcloud.yml/badge.svg)](https://github.com/ByronWilliamsCPA/cookiecutter-python-template/actions/workflows/sonarcloud.yml)
5-
[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=ByronWilliamsCPA_cookiecutter-python-template&metric=alert_status)](https://sonarcloud.io/summary/new_code?id=ByronWilliamsCPA_cookiecutter-python-template)
6-
[![Security Rating](https://sonarcloud.io/api/project_badges/measure?project=ByronWilliamsCPA_cookiecutter-python-template&metric=security_rating)](https://sonarcloud.io/summary/new_code?id=ByronWilliamsCPA_cookiecutter-python-template)
7-
[![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=ByronWilliamsCPA_cookiecutter-python-template&metric=sqale_rating)](https://sonarcloud.io/summary/new_code?id=ByronWilliamsCPA_cookiecutter-python-template)
8-
[![Code Smells](https://sonarcloud.io/api/project_badges/measure?project=ByronWilliamsCPA_cookiecutter-python-template&metric=code_smells)](https://sonarcloud.io/summary/new_code?id=ByronWilliamsCPA_cookiecutter-python-template)
94

105
This folder contains a complete, production-ready cookiecutter template for starting new Python projects.
116

@@ -296,16 +291,11 @@ my_awesome_project/
296291

297292
## 🔍 SonarCloud Setup (Optional)
298293

299-
Both this template repository and generated projects support SonarCloud for continuous code quality and security analysis.
300-
301-
### For Template Repository (This Repo)
302-
303-
The template repository itself is configured with SonarCloud to analyze hooks and template files:
304-
305-
1. **Project Already Created**: `ByronWilliamsCPA_cookiecutter-python-template`
306-
2. **Token Configured**: `SONAR_TOKEN` secret added to GitHub organization
307-
3. **Workflow Enabled**: `.github/workflows/sonarcloud.yml` runs on push/PR
308-
4. **Dashboard**: [View SonarCloud Dashboard](https://sonarcloud.io/project/overview?id=ByronWilliamsCPA_cookiecutter-python-template)
294+
Generated projects support SonarCloud for continuous code quality and security analysis.
295+
This template repository does not run SonarCloud analysis: the Jinja2 template body is not
296+
statically analyzable as plain Python, and analysis was failing with a `curl 403` from the
297+
quality-gate API. Generated child projects opt into their own SonarCloud analysis via the
298+
rendered config that ships inside the template output directory.
309299

310300
### For Generated Projects
311301

@@ -357,7 +347,7 @@ Generated projects include:
357347

358348
### Analysis Method
359349

360-
Both template and generated projects use **CI-Based Analysis** (not Automatic):
350+
Generated projects use **CI-Based Analysis** (not Automatic):
361351

362352
- ✅ Full Python language support
363353
- ✅ Test coverage integration

0 commit comments

Comments
 (0)