You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SonarQube Developer版Bitbucket PR扫描后续配置步骤咨询

Bitbucket Server PR Scanning with SonarQube Developer Edition: Step-by-Step Guide

Hey there! Since you've already got the Developer Edition trial set up and PR decoration configured, let's jump right into getting PR scans working smoothly. Here's exactly what you need to do:

1. Prep Your Scanning Environment First

Before diving into parameters, double-check these basics to avoid headaches later:

  • Your SonarQube server can reach your Bitbucket Server instance (network connectivity is solid)
  • The machine running the scan (CI/CD server or local dev machine) has:
    • The latest SonarScanner CLI installed
    • Access to both SonarQube and Bitbucket Server (to pull code and send scan results)
    • Permissions to read the Bitbucket repository (use SSH keys or a Bitbucket personal access token for private repos)

2. Core PR Scanning Parameters You Need

These parameters tell SonarQube this is a PR-specific scan, not a regular branch scan. Here's what each one does:

  • sonar.projectKey: Must match the exact project key you created in SonarQube
  • sonar.pullrequest.key: The ID of your Bitbucket PR (found in the PR URL, e.g., 123 for http://bitbucket-server/proj/repo/pull-requests/123)
  • sonar.pullrequest.base: The target branch your PR is merging into (e.g., main, develop)
  • sonar.pullrequest.branch: The source branch of your PR (e.g., feature/user-profile-update)
  • sonar.pullrequest.bitbucket.server.projectKey: The key of your Bitbucket project (visible in Bitbucket project settings)
  • sonar.pullrequest.bitbucket.server.repositorySlug: The "slug" of your Bitbucket repo (last part of the repo URL, e.g., my-ecommerce-app for http://bitbucket-server/proj/my-ecommerce-app)
  • Standard SonarQube connection params: sonar.host.url (your SonarQube server URL) and sonar.login (a SonarQube user token—create this in your SonarQube profile settings, never use your password!)

3. Where to Put These Parameters

Placement depends on how you're running the scan—here are the most common scenarios:

Option A: Running SonarScanner CLI Manually (Great for Testing)

Pass parameters directly in the command line:

sonar-scanner \
  -Dsonar.projectKey=my-bitbucket-project \
  -Dsonar.host.url=http://my-sonarqube-server:9000 \
  -Dsonar.login=sqp_abc123xyz456... \
  -Dsonar.pullrequest.key=42 \
  -Dsonar.pullrequest.base=main \
  -Dsonar.pullrequest.branch=feature/checkout-flow \
  -Dsonar.pullrequest.bitbucket.server.projectKey=MY-BB-PROJ \
  -Dsonar.pullrequest.bitbucket.server.repositorySlug=my-ecommerce-app

You can store static params (like sonar.projectKey, sonar.host.url) in a sonar-project.properties file at your repo root, but keep dynamic PR-specific params (like sonar.pullrequest.key) in the command line—they change every PR.

Option B: Bitbucket Pipelines (Auto-Scan on PR Creation)

Use Bitbucket's built-in environment variables to auto-populate PR details, so you don't have to hardcode anything. Add this to your bitbucket-pipelines.yml:

pipelines:
  pull-requests:
    '**':  # Trigger on all PRs
      - step:
          name: SonarQube PR Analysis
          image: sonarsource/sonar-scanner-cli:latest
          script:
            - sonar-scanner \
                -Dsonar.projectKey=my-bitbucket-project \
                -Dsonar.host.url=${SONAR_HOST_URL} \
                -Dsonar.login=${SONAR_TOKEN} \
                -Dsonar.pullrequest.key=${BITBUCKET_PR_ID} \
                -Dsonar.pullrequest.base=${BITBUCKET_PR_DESTINATION_BRANCH} \
                -Dsonar.pullrequest.branch=${BITBUCKET_BRANCH} \
                -Dsonar.pullrequest.bitbucket.server.projectKey=${BITBUCKET_PROJECT_KEY} \
                -Dsonar.pullrequest.bitbucket.server.repositorySlug=${BITBUCKET_REPO_SLUG}

Store SONAR_HOST_URL and SONAR_TOKEN as repository variables in Bitbucket (Settings > Repository variables) to keep them secure.

Option C: Jenkins Pipeline

If you're using Jenkins with the Bitbucket Branch Source plugin, it auto-exposes PR-related variables. Here's a sample pipeline snippet:

pipeline {
  agent any
  stages {
    stage('SonarQube PR Scan') {
      steps {
        withSonarQubeEnv('My SonarQube Server') {  // Match your SonarQube server config in Jenkins
          sh '''
            sonar-scanner \
              -Dsonar.projectKey=my-bitbucket-project \
              -Dsonar.pullrequest.key=${CHANGE_ID} \
              -Dsonar.pullrequest.base=${CHANGE_TARGET} \
              -Dsonar.pullrequest.branch=${BRANCH_NAME} \
              -Dsonar.pullrequest.bitbucket.server.projectKey=MY-BB-PROJ \
              -Dsonar.pullrequest.bitbucket.server.repositorySlug=my-ecommerce-app
          '''
        }
      }
    }
  }
}

4. Verify It's Working

Once you trigger the scan (manually or via CI/CD):

  1. Check the SonarQube dashboard—you should see a new entry under Pull Requests for your PR
  2. Head back to your Bitbucket PR page: the PR decoration should show scan results (code smells, vulnerabilities, and whether it passed your quality gate)

Pro Tips

  • Set up a quality gate in SonarQube (Project Settings > Quality Gates) to enforce rules like "no critical vulnerabilities" before merging PRs
  • If you hit issues, check the SonarScanner logs first—they'll flag missing parameters or connectivity problems

内容的提问来源于stack exchange,提问作者Devine92

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:16:23