You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将CMT++、CPD、Coverity、Cobertura报告推送至C++项目SonarQube并求插件推荐

Nice question! Let's walk through exactly how to get your CMT++, CPD, Coverity, and Cobertura XML reports into your C++ SonarQube project, including the plugins you'll need and step-by-step setup.

Required Plugins

First, you'll need a mix of core and supplementary plugins to handle these different report types:

  • SonarCFamily: Non-negotiable for C++ projects—it's SonarQube's official plugin that provides core analysis support for C/C++ code. Install this first.
  • SonarCobertura Plugin: Adds support for importing Cobertura-style coverage reports.
  • SonarQube Coverity Plugin: Enables integration with Coverity's static analysis results.
  • For CPD: SonarQube includes built-in CPD (Copy/Paste Detector) functionality, so no extra plugin is needed if you want to use your pre-generated external report.
Step-by-Step Implementation

1. Install & Enable Plugins on SonarQube Server

  1. Log into your SonarQube instance.
  2. Navigate to the Marketplace (under Administration > Marketplace).
  3. Search for and install the three plugins listed above (SonarCFamily, SonarCobertura, SonarQube Coverity).
  4. Restart your SonarQube server to activate the plugins.

2. Configure SonarScanner & Project Basics

We'll use SonarScanner CLI for this workflow (it's the most flexible for C++ projects):

  1. Install SonarScanner CLI on your build machine, and configure it with your SonarQube server URL and authentication token (either in sonar-scanner.properties or via command-line flags).
  2. In your C++ project root, create a sonar-project.properties file with basic project config:
    sonar.projectKey=your-unique-project-key
    sonar.projectName=Your C++ Project Name
    sonar.projectVersion=1.0
    sonar.sources=src/  # Update to your actual source code directory
    sonar.language=cpp
    sonar.sourceEncoding=UTF-8
    

3. Integrate Each Report Type

Add these configurations to your sonar-project.properties file (or pass them as command-line -D flags when running the scanner):

CMT++ XML Report

CMT++ results count as external static analysis issues, so use the generic external issues parameter:

sonar.externalIssuesReportPaths=path/to/your/cmtpp-report.xml

CPD XML Report

Even though SonarQube has built-in CPD, you can import your pre-generated report with:

sonar.cpd.reportPaths=path/to/your/cpd-report.xml

Coverity XML Report

First, export your Coverity results to a SonarQube-compatible XML format using Coverity's tools:

cov-format-export --dir cov-int --output-format xml --output-file path/to/your/coverity-report.xml

Then add this config to your project properties:

sonar.coverity.reportPath=path/to/your/coverity-report.xml

Cobertura Coverage Report

For C++ projects, use the C++-specific Cobertura parameter (not the Java one):

sonar.cpp.cobertura.reportPaths=path/to/your/cobertura-coverage.xml

4. Run the Scan & Push Results

From your project root, execute the SonarScanner to push all reports to SonarQube:

sonar-scanner

If you prefer passing parameters via command line instead of using the properties file, run something like:

sonar-scanner -Dsonar.projectKey=your-project-key -Dsonar.host.url=http://your-sonarqube-server -Dsonar.login=your-auth-token -Dsonar.externalIssuesReportPaths=path/to/cmtpp-report.xml -Dsonar.cpp.cobertura.reportPaths=path/to/cobertura-coverage.xml
Key Notes to Avoid Issues
  • Double-check that all report paths are correct (use absolute paths if relative paths aren't working).
  • For large C++ projects, allocate more memory to SonarScanner by adding -Xmx4G (or higher) to the scanner's JVM arguments.
  • Ensure your SonarQube authentication token has Execute Analysis permissions for the target project.
  • Verify that your Coverity export uses a format compatible with the installed SonarQube Coverity plugin (stick to latest tool versions for best compatibility).

内容的提问来源于stack exchange,提问作者Ure Ramya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:57:39