JS, TS, Go, Python, PHP, etc. project

Using YAML or the Azure Classic editor to create the Azure build pipeline for JavaScript, TypeScript, Go, Python, PHP, and other projects.

This page explains how to add the SonarQube Community Build analysis to your Azure build pipeline for projects that are not Maven, Gradle, or .NET.

Before you begin, read Azure Pipelines integration overview.

Once you have created your project in SonarQube Community Build and set up feature integration for your project, see Creating and configuring your project and Setting up project integration, you can add the SonarQube analysis to your Azure build pipeline.

To create your Azure build pipeline, you can use either YAML or the Azure Classic editor.

  • The use of the Classic editor is not always possible (e.g. if your code is stored on GitHub).

  • If you use YAML, Sonar can provide you with YAML templates or code examples.

If you need to use a specific scanner version, see Using various features.

Using YAML

Add the following SonarQube tasks to your YAML pipeline:

  1. Before your build task, add a Prepare Analysis Configuration task.

  2. After your build task, add a Run Code Analysis task.

  3. After the Run Code Analysis task, add a Publish Quality Gate Result task.

See the #YAML file example below. See also our YAML pipeline templates. For information about the SonarQube task inputs, see SonarQube tasks for Azure Pipelines.

Make sure the SonarQube task version used in your YAML file is the correct one. For example, in SonarQubePrepare@7, 7 should correspond to the version of the Azure DevOps extension you’re using.

YAML file example
trigger:
- master # or the name of your main branch
- feature/*

steps:
 # Checkout the repository
 - checkout: self
 
 # Disable shallow fetch
   fetchDepth: 0

# Prepare Analysis Configuration task
- task: SonarQubePrepare@7
  inputs:
    SonarQube: '<YourSonarqubeServerEndpoint>'
    scannerMode: 'cli'
    configMode: 'manual'
    cliProjectKey: '<YourProjectKey>'

# Add your build task(s) here

# Run Code Analysis task
- task: SonarQubeAnalyze@7
  inputs:
    jdkversion: 'JAVA_HOME_17_X64'

# Publish Quality Gate Result task
- task: SonarQubePublish@7
  inputs:
    pollingTimeoutSec: '300'

Using the Classic editor

In the procedure below, the manual configuration mode is used to define analysis parameters at the pipeline level. You may use the sonar-project.properties file instead (or another specified configuration file). For more information, see Using various features.

Proceed as follows:

  1. In the Azure DevOps’ Classic editor, create or edit your build pipeline.

  2. Add a Prepare Analysis Configuration task before your build task:

    • In SonarQube Service Endpoint, select the SonarQube service connection you created in Setting up project integration.

    • Under Choose a way to run the analysis, select Use Standalone SonarScanner CLI.

    • Select the Manually provide configuration mode.

    • In the Project key field, enter your project key.

  3. Add a new Run Code Analysis task after your build task.

  4. Add a new Publish quality gate Result on your build pipeline summary.

  5. Ensure that the pipeline runs automatically for all the branches you want:

    • Under the Triggers tab of your pipeline, select Enable continuous integration and select all the branches for which you want SonarQube Community Build analysis to run automatically.

  6. Save your pipeline.

Last updated

Was this helpful?