SonarQube Developer版Bitbucket PR扫描后续配置步骤咨询
Hey there! Since you've already got the Developer Edition trial set up and PR decoration configured, let's jump right into getting PR scans working smoothly. Here's exactly what you need to do:
1. Prep Your Scanning Environment First
Before diving into parameters, double-check these basics to avoid headaches later:
- Your SonarQube server can reach your Bitbucket Server instance (network connectivity is solid)
- The machine running the scan (CI/CD server or local dev machine) has:
- The latest SonarScanner CLI installed
- Access to both SonarQube and Bitbucket Server (to pull code and send scan results)
- Permissions to read the Bitbucket repository (use SSH keys or a Bitbucket personal access token for private repos)
2. Core PR Scanning Parameters You Need
These parameters tell SonarQube this is a PR-specific scan, not a regular branch scan. Here's what each one does:
sonar.projectKey: Must match the exact project key you created in SonarQubesonar.pullrequest.key: The ID of your Bitbucket PR (found in the PR URL, e.g.,123forhttp://bitbucket-server/proj/repo/pull-requests/123)sonar.pullrequest.base: The target branch your PR is merging into (e.g.,main,develop)sonar.pullrequest.branch: The source branch of your PR (e.g.,feature/user-profile-update)sonar.pullrequest.bitbucket.server.projectKey: The key of your Bitbucket project (visible in Bitbucket project settings)sonar.pullrequest.bitbucket.server.repositorySlug: The "slug" of your Bitbucket repo (last part of the repo URL, e.g.,my-ecommerce-appforhttp://bitbucket-server/proj/my-ecommerce-app)- Standard SonarQube connection params:
sonar.host.url(your SonarQube server URL) andsonar.login(a SonarQube user token—create this in your SonarQube profile settings, never use your password!)
3. Where to Put These Parameters
Placement depends on how you're running the scan—here are the most common scenarios:
Option A: Running SonarScanner CLI Manually (Great for Testing)
Pass parameters directly in the command line:
sonar-scanner \ -Dsonar.projectKey=my-bitbucket-project \ -Dsonar.host.url=http://my-sonarqube-server:9000 \ -Dsonar.login=sqp_abc123xyz456... \ -Dsonar.pullrequest.key=42 \ -Dsonar.pullrequest.base=main \ -Dsonar.pullrequest.branch=feature/checkout-flow \ -Dsonar.pullrequest.bitbucket.server.projectKey=MY-BB-PROJ \ -Dsonar.pullrequest.bitbucket.server.repositorySlug=my-ecommerce-app
You can store static params (like sonar.projectKey, sonar.host.url) in a sonar-project.properties file at your repo root, but keep dynamic PR-specific params (like sonar.pullrequest.key) in the command line—they change every PR.
Option B: Bitbucket Pipelines (Auto-Scan on PR Creation)
Use Bitbucket's built-in environment variables to auto-populate PR details, so you don't have to hardcode anything. Add this to your bitbucket-pipelines.yml:
pipelines: pull-requests: '**': # Trigger on all PRs - step: name: SonarQube PR Analysis image: sonarsource/sonar-scanner-cli:latest script: - sonar-scanner \ -Dsonar.projectKey=my-bitbucket-project \ -Dsonar.host.url=${SONAR_HOST_URL} \ -Dsonar.login=${SONAR_TOKEN} \ -Dsonar.pullrequest.key=${BITBUCKET_PR_ID} \ -Dsonar.pullrequest.base=${BITBUCKET_PR_DESTINATION_BRANCH} \ -Dsonar.pullrequest.branch=${BITBUCKET_BRANCH} \ -Dsonar.pullrequest.bitbucket.server.projectKey=${BITBUCKET_PROJECT_KEY} \ -Dsonar.pullrequest.bitbucket.server.repositorySlug=${BITBUCKET_REPO_SLUG}
Store SONAR_HOST_URL and SONAR_TOKEN as repository variables in Bitbucket (Settings > Repository variables) to keep them secure.
Option C: Jenkins Pipeline
If you're using Jenkins with the Bitbucket Branch Source plugin, it auto-exposes PR-related variables. Here's a sample pipeline snippet:
pipeline { agent any stages { stage('SonarQube PR Scan') { steps { withSonarQubeEnv('My SonarQube Server') { // Match your SonarQube server config in Jenkins sh ''' sonar-scanner \ -Dsonar.projectKey=my-bitbucket-project \ -Dsonar.pullrequest.key=${CHANGE_ID} \ -Dsonar.pullrequest.base=${CHANGE_TARGET} \ -Dsonar.pullrequest.branch=${BRANCH_NAME} \ -Dsonar.pullrequest.bitbucket.server.projectKey=MY-BB-PROJ \ -Dsonar.pullrequest.bitbucket.server.repositorySlug=my-ecommerce-app ''' } } } } }
4. Verify It's Working
Once you trigger the scan (manually or via CI/CD):
- Check the SonarQube dashboard—you should see a new entry under Pull Requests for your PR
- Head back to your Bitbucket PR page: the PR decoration should show scan results (code smells, vulnerabilities, and whether it passed your quality gate)
Pro Tips
- Set up a quality gate in SonarQube (Project Settings > Quality Gates) to enforce rules like "no critical vulnerabilities" before merging PRs
- If you hit issues, check the SonarScanner logs first—they'll flag missing parameters or connectivity problems
内容的提问来源于stack exchange,提问作者Devine92

