You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SonarCloud是否支持GitHub PR工作流中Python装饰性消息?配置后未收到消息

SonarCloud PR装饰消息不显示问题

问题描述

我使用SonarCloud通用工作流配置后,代码分析可正常完成且结果能在SonarCloud网站查看,但仓库的Pull Request中始终未收到SonarCloud机器人发送的装饰性消息。

相关配置

Workflow 配置

name: CI

on:
  push:
    branches: [ "main", "develop" ]
  pull_request:
    branches: [ "main", "develop" ]
    types: [opened, synchronize, reopened]
  workflow_dispatch:

permissions:
  pull-requests: read # allows SonarCloud to decorate PRs with analysis results

jobs:
  sonar_cloud_report:
    runs-on: ubuntu-latest  
    
    steps:
      - uses : actions/checkout@v3
      - uses: ./.github/actions/dependencies
      - uses: SonarSource/sonarcloud-github-action@master
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}  # Needed to get PR information
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}   # Generate a token on Sonarcloud.io, add it to the secrets of this repo with the name SONAR_TOKEN (Settings > Secrets > Actions > add new repository secret)
        with:
          # Additional arguments for the sonarcloud scanner
          args:
            # Unique keys of your project and organization. You can find them in SonarCloud > Information (bottom-left menu)
            # mandatory
            -Dsonar.projectKey=XXX
            -Dsonar.organization=XXX
            -Dsonar.scm.provider=git
            # Comma-separated paths to directories containing main source files.
            #-Dsonar.sources= # optional, default is project base directory
            # When you need the analysis to take place in a directory other than the one from which it was launched
            #-Dsonar.projectBaseDir= # optional, default is .
            # Comma-separated paths to directories containing test source files.
            #-Dsonar.tests= # optional. For more info about Code Coverage, please refer to https://docs.sonarcloud.io/enriching/test-coverage/overview/
            # Adds more detail to both client and server-side analysis logs, activating DEBUG mode for the scanner, and adding client-side environment variables and system properties to the server-side log of analysis report processing.
            #-Dsonar.verbose= # optional, default is false
      - name: SonarCloud Scan
        uses: SonarSource/sonarcloud-github-action@master
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}  # Needed to get PR information, if any
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} 

sonar-project.properties 配置

sonar.projectKey=XXX
sonar.organization=XXX
sonar.verbose=true
sonar.python.coverage.reportPaths=coverage.xml

# This is the name and version displayed in the SonarCloud UI.
#sonar.projectName=XXX
#sonar.projectVersion=1.0

# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.
#sonar.sources=.

# Encoding of the source code. Default is default system encoding
#sonar.sourceEncoding=UTF-8

解决建议

  • 删除冗余扫描步骤:Workflow中连续执行了两次SonarSource/sonarcloud-github-action@master,第二次扫描会干扰第一次的PR关联逻辑,保留其中一个扫描步骤即可(建议保留带参数的版本,或合并参数到单个步骤)。
  • 调整权限配置:当前pull-requests: read仅能读取PR信息,无法让SonarCloud写入装饰评论,需修改权限:
    permissions:
      pull-requests: write
      contents: read
    
  • 验证Token与事件关联:确保GITHUB_TOKEN正确传递,且Workflow在PR事件触发时能自动获取上下文,无需手动指定PR参数。
  • 检查SonarCloud项目设置:登录SonarCloud进入对应项目设置,确认已开启Pull Request装饰功能,且GitHub仓库关联配置正确。

内容的提问来源于stack exchange,提问作者Axeltherabbit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 18:10:47