SonarScanner for Gradle runs SonarQube analysis as part of a Gradle build and sends the results to SonarQube Server or SonarQube Cloud.
Read the SonarScanner for Gradle documentation, or learn more about the SonarQube product family.
https://redirect.sonarsource.com/doc/gradle.html
For support questions ("How do I?", "I got this error, why?", ...), please head to the SonarSource forum. There are chances that a question similar to yours has already been answered.
Be aware that this forum is a community, so the standard pleasantries ("Hi", "Thanks", ...) are expected. And if you don't get an answer to your thread, you should sit on your hands for at least three days before bumping it. Operators are not standing by. :-)
If you would like to see a new feature, please create a new thread in the forum "Suggest new features".
Please be aware that we are not actively looking for feature contributions. The truth is that it's extremely difficult for someone outside SonarSource to comply with our roadmap and expectations. Therefore, we typically only accept minor cosmetic changes and typo fixes.
With that in mind, if you would like to submit a code contribution, please create a pull request for this repository. Please explain your motives to contribute this change: what problem you are trying to fix, what improvement you are trying to make.
Make sure that you follow our code style and all tests are passing.
Then, one of the members of our team will carefully review your pull request. You might be asked at this point for clarifications or your pull request might be rejected if we decide that it doesn't fit our roadmap and vision for the product.
A mature software vulnerability treatment process is a cornerstone of a robust information security management system. Contributions from the community play an important role in the evolution and security of our products, and in safeguarding the security and privacy of our users.
If you believe you have discovered a security vulnerability in Sonar's products, we encourage you to report it immediately.
To responsibly report a security issue, please email us at security@sonarsource.com. Sonar’s security team will acknowledge your report, guide you through the next steps, or request additional information if necessary. Customers with a support contract can also report the vulnerability directly through the support channel.
For security vulnerabilities found in third-party libraries, please also contact the library's owner or maintainer directly.
For more information about disclosing a security vulnerability to Sonar, please refer to our community post: Responsible Vulnerability Disclosure.
To build the plugin and run the tests, you will need Java 21 and android SDK.
Prerequisites:
# install java, Maven, Gradle and Android SDK command-line tools
mise install
# use java 21
mise shell java@21
# install android platform
yes 2> /dev/null | sdkmanager --sdk_root="${ANDROID_HOME}" --licenses
sdkmanager --sdk_root="${ANDROID_HOME}" "platform-tools" "platforms;android-36" "build-tools;36.0.0"Build and install a SNAPSHOT in the local Maven repository:
./gradlew clean build publishToMavenLocalWhen dependencies change, regenerate all lockfiles by resolving the project dependencies,
buildscript and plugin classpath, buildSrc dependencies, and CycloneDX configurations:
./gradlew :buildSrc:dependencies dependencies buildEnvironment cyclonedxBom --write-locks
git diff -- gradle.lockfile buildscript-gradle.lockfile buildSrc/gradle.lockfileMaven Local is excluded from build dependency resolution so normal builds, CI, and lockfile generation use consistent published metadata rather than POM-only metadata that may be present in a developer's local repository.
When the plugin is applied to a project, it will add to that project the Sonar task. It will also add to the project and all its subprojects the Sonar extension.
For multi-module projects, the plugin will only apply to the first project where it gets called. The goal is to allow the usage of allprojects {}, for example.
Sonar extension
The sonar extension enables an easy configuration of a project with the Domain Specific Language.
Sonar task
The Sonar task has the name sonar, so it can be executed by calling ./gradlew sonar. It collects information from the project and all its subprojects, generating the properties for the analysis. Then, it runs the SonarScanner analysis using all those properties.
The task depends on all compile and test tasks of all projects (except for skipped projects).
If all projects are skipped (by adding skipProject=true to the sonar DSL), the analysis won't execute.
A composite build can be used to substitute plugins with an included build.
In the target project, apply the sonarqube plugin:
plugins {
id 'org.sonarqube'
}
Run with:
./gradlew sonar --include-build /path/to/sonar-scanner-gradle
See the previous point about including the plugin's build when building a target project. To debug, simply add the parameter:
./gradlew sonar --include-build /path/to/sonar-scanner-gradle/build/classes/java/main/ -Dorg.gradle.debug=true
Now debug remotely by connecting to the port 5005.
By default, Integration Tests are skipped during the build. To run them, you need to follow these steps:
- Install the SNAPSHOT version of the root project in the local Maven repository.
- Import the
integationTestsproject as a Maven project and ensure that Android SDK is set. - Set
ANDROID_HOMEenvironment variable - Run the following command from the
integrationTestsproject:# unset environment variables that could interfere with the test execution unset SONAR_SCANNER_OPTS # mvn --errors clean verify -Dgradle.version="<gradle-version>" -DandroidGradle.version="<android-gradle-version>" -Dsonar.runtimeVersion="sonar-runtime-version" # for example: cd integrationTests mvn --errors clean verify -Dgradle.version="9.5.1" -DandroidGradle.version="9.2.0" -Dsonar.runtimeVersion="LATEST_RELEASE[26.4]"
buildscript {
repositories {
mavenCentral()
mavenLocal()
}
dependencies { classpath 'org.sonarsource.scanner.gradle:sonarqube-gradle-plugin:<THE VERSION>' }
}
apply plugin: 'org.sonarqube'Follow the Scanner for Gradle Release Process
https://plugins.gradle.org/docs/publish-plugin
./gradlew release
Copyright 2011-2025 SonarSource.
Licensed under the GNU Lesser General Public License, Version 3.0)