如何将CMT++、CPD、Coverity、Cobertura报告推送至C++项目SonarQube并求插件推荐
Nice question! Let's walk through exactly how to get your CMT++, CPD, Coverity, and Cobertura XML reports into your C++ SonarQube project, including the plugins you'll need and step-by-step setup.
First, you'll need a mix of core and supplementary plugins to handle these different report types:
- SonarCFamily: Non-negotiable for C++ projects—it's SonarQube's official plugin that provides core analysis support for C/C++ code. Install this first.
- SonarCobertura Plugin: Adds support for importing Cobertura-style coverage reports.
- SonarQube Coverity Plugin: Enables integration with Coverity's static analysis results.
- For CPD: SonarQube includes built-in CPD (Copy/Paste Detector) functionality, so no extra plugin is needed if you want to use your pre-generated external report.
1. Install & Enable Plugins on SonarQube Server
- Log into your SonarQube instance.
- Navigate to the Marketplace (under Administration > Marketplace).
- Search for and install the three plugins listed above (SonarCFamily, SonarCobertura, SonarQube Coverity).
- Restart your SonarQube server to activate the plugins.
2. Configure SonarScanner & Project Basics
We'll use SonarScanner CLI for this workflow (it's the most flexible for C++ projects):
- Install SonarScanner CLI on your build machine, and configure it with your SonarQube server URL and authentication token (either in
sonar-scanner.propertiesor via command-line flags). - In your C++ project root, create a
sonar-project.propertiesfile with basic project config:sonar.projectKey=your-unique-project-key sonar.projectName=Your C++ Project Name sonar.projectVersion=1.0 sonar.sources=src/ # Update to your actual source code directory sonar.language=cpp sonar.sourceEncoding=UTF-8
3. Integrate Each Report Type
Add these configurations to your sonar-project.properties file (or pass them as command-line -D flags when running the scanner):
CMT++ XML Report
CMT++ results count as external static analysis issues, so use the generic external issues parameter:
sonar.externalIssuesReportPaths=path/to/your/cmtpp-report.xml
CPD XML Report
Even though SonarQube has built-in CPD, you can import your pre-generated report with:
sonar.cpd.reportPaths=path/to/your/cpd-report.xml
Coverity XML Report
First, export your Coverity results to a SonarQube-compatible XML format using Coverity's tools:
cov-format-export --dir cov-int --output-format xml --output-file path/to/your/coverity-report.xml
Then add this config to your project properties:
sonar.coverity.reportPath=path/to/your/coverity-report.xml
Cobertura Coverage Report
For C++ projects, use the C++-specific Cobertura parameter (not the Java one):
sonar.cpp.cobertura.reportPaths=path/to/your/cobertura-coverage.xml
4. Run the Scan & Push Results
From your project root, execute the SonarScanner to push all reports to SonarQube:
sonar-scanner
If you prefer passing parameters via command line instead of using the properties file, run something like:
sonar-scanner -Dsonar.projectKey=your-project-key -Dsonar.host.url=http://your-sonarqube-server -Dsonar.login=your-auth-token -Dsonar.externalIssuesReportPaths=path/to/cmtpp-report.xml -Dsonar.cpp.cobertura.reportPaths=path/to/cobertura-coverage.xml
- Double-check that all report paths are correct (use absolute paths if relative paths aren't working).
- For large C++ projects, allocate more memory to SonarScanner by adding
-Xmx4G(or higher) to the scanner's JVM arguments. - Ensure your SonarQube authentication token has Execute Analysis permissions for the target project.
- Verify that your Coverity export uses a format compatible with the installed SonarQube Coverity plugin (stick to latest tool versions for best compatibility).
内容的提问来源于stack exchange,提问作者Ure Ramya

