You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SonarQube未扫描C文件且Cppcheck结果未发布问题求助

问题描述

我在运行SonarQube并配置了cxx插件,已设置sonar.cppcheck.reportpaths=./test.xml,但SonarQube网站仅扫描Python和HTML文件,未处理C文件,也看不到Cppcheck的检测结果。

我的sonar-project.properties内容如下:

# Project identification
sonar.projectKey=sonar
sonar.projectName=sonarqube_project
sonar.projectVersion=1.0
 
# Leave sonar.sources empty
sonar.sources=test
#sonar.language=cpp
sonar.language=cxx
sonar.sourceEncoding=UTF-8
sonar.cxx.file.suffixes=.c,.h
sonar.cppcheck.reportPaths=./test.xml
#sonar.cxx.compiler.parser=MSBuild
#sonar.cxx.compiler.reportPath=*.log
#sonar.cxx.compiler.charset=UTF-8S

调用SAST扫描的远程流水线配置:

#version: v4.3.2
variables:
    SAST_IMAGE: "cdn.harbor.global.lmco.com/lmc.eo.asap/lmco-security/static-code-scanner:latest"
    ENABLE_SAST_SCANS: "true"
    SAST_ALLOW_FAIL: "false"
    # See documentation for additional variables https://pipeline-cSatalog.global.lmco.com/#/pipelines/sast-scans/docs/sast-basic.md

    # variable for tracking pipeline usage
    SWF_PIPELINE_METRICS_MODULES_SAST_SONARQUBE: "true"
.sonarqube-scan:
    image: $SAST_IMAGE
    stage: sast
    variables:
        SAST_SCAN: "sonarqube"
        NEXUS_URL: "https://nexus.global.lmco.com"
    before_script:
        - echo -e " -- Docs -- 
 pipeline_module 
 - modules/sast-sonarqube.gitlab-ci.yml 
 expected files 
 - none 
 variables 
 - ADDITIONAL_PATH 			  ${ADDITIONAL_PATH} 
 - ENFORCE_RELEASE_GATE 		  ${ENFORCE_RELEASE_GATE} 
 - SCAN_RESULTS_REVIEWERS_NTIDS  ${SCAN_RESULTS_REVIEWERS_NTIDS} 
 - ENABLE_RESULTS_EMAIL 		  ${ENABLE_RESULTS_EMAIL} 
"
        - "if [ -z ${CI_PROJECT_NAME+x} ]; then
  echo "**********************************************************************************************************"
  echo -e "\e[91mYou appear to be missing variables normally provided by GitLab. If you are executing \e[0m" 
  echo -e "\e[91myour pipeline from Jenkins, variable mapping documentation can be found here: \e[0m"
  echo -e "\e[34mhttps://docs.us.lmco.com/display/CASAP/ASAP-General-008+-+How+to+Configure+Security+Scanning+for+Bitbucket \e[0m"
  echo "**********************************************************************************************************"
  exit 1
fi
"
        - >
          if [ -n "${ADDITIONAL_PATH}" ] && [ "$ADDITIONAL_PATH" != "." ]; then

            FILE="${ADDITIONAL_PATH}/sonar-project.properties"
            if [ -f "$FILE" ];
            then
              echo "Copying sonar-project.properties to repo root."
              cp "$FILE" "./sonar-project.properties"
            fi
          fi

    script:
        - python /static-code-scan.py
    artifacts:
        paths:
            - sonarqubescan-metrics.json
        when: always
sonarqube-scan:
    extends: .sonarqube-scan
    rules:
        - if: '$ENABLE_SAST_SCANS == "false"'
          when: never
        - if: '$SAST_ALLOW_FAIL=="true"'
          allow_failure: true
        - if: '$SAST_ALLOW_FAIL=="false"'
          allow_failure: false

排查与解决建议

1. 移除过时的sonar.language配置

SonarQube新版本已弃用sonar.language参数,强制指定语言会导致SonarQube忽略其他类型文件。删除sonar.language=cxx这一行,让系统自动识别项目中的语言类型,包括C/C++文件。

2. 确认源码路径的有效性

检查sonar.sources=test配置:

  • 确保项目根目录下存在test文件夹,且该文件夹内确实有.c/.h文件
  • 若路径不正确,修正为C文件所在的实际目录(比如sonar.sources=.表示扫描根目录下所有文件)

3. 验证Cppcheck报告的正确性

  • 确认./test.xml文件存在且为Cppcheck生成的有效XML报告,手动打开文件检查是否包含C文件的检测结果
  • 若报告路径错误,修正为实际的报告文件路径(比如./cppcheck-results/test.xml)

4. 检查流水线镜像的环境配置

  • 确认使用的SAST_IMAGE中已正确安装SonarQube Cxx插件,且插件版本与SonarQube服务器版本兼容
  • 查看流水线日志,确认SonarQube扫描命令是否正确加载了sonar-project.properties中的配置,特别是sonar.cxx.file.suffixes和sonar.cppcheck.reportPaths参数

5. 修复配置中的语法错误

sonar-project.properties中注释行#sonar.cxx.compiler.charset=UTF-8S多了一个S,即使当前未启用,建议修正为UTF-8,避免后续启用编译器报告时出现编码错误

内容的提问来源于stack exchange,提问作者patricia lomber

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 03:52:36