Conversation
…cripts Fixes SonarCloud shell:S6506 (curl --proto '=https' to block downgrade redirects), shell:S5332 (http to https download URLs and usage example), shell:S6505 (npm --ignore-scripts). Eclipse download switched from wget with --no-check-certificate to verifying curl.
Fixes SonarCloud githubactions:S7637. Tags are mutable and can be hijacked; pinning to full commit SHA with the version kept as trailing comment. Upgrades: korthout/backport-action 4.6.0 to 4.7.0, mikepenz/action-junit-report 4.3.1 to 6.5.0, SonarSource/sonarqube-scan-action 7.1.0 to 8.3.0, geekyeggo/delete-artifact 5.1.0 to 6.0.0. All inputs used by the workflows verified compatible with the new versions.
Monthly updates for SHA-pinned third-party actions so pinned versions do not go stale.
Fixes SonarCloud typescript:S2933 (541 issues). Mechanical transformation: add readonly to fields assigned only in the constructor. Decorated members (@Input/@Output/@ViewChild) excluded as the framework assigns them. Verified with tsc --noEmit on all 8 frontend projects: zero read-only assignment violations.
WalkthroughWarning Review details and warnings were omitted to fit the comment limit. |
|
New Issues (Top 33 out of 280)Checkmarx found the following issues in this Pull Request
Fixed Issues (84)Great job! The following issues were fixed in this Pull Request
Use @Checkmarx to take action directly from this PR:
Try it: |
…ripts Fixes SonarCloud javascript:S3504 (9 issues). Mechanical transformation: const when never reassigned, let otherwise. Verified with node --check on all 9 files: OK, no var remaining.
Fixes SonarCloud shelldre:S7688. All files use a bash shebang so [[ ]] is safe; run-tests.sh keeps single brackets with NOSONAR as it must stay dash-readable before re-exec. Verified with bash -n on all 6 files.
Fixes SonarCloud docker:S7029. COPY is sufficient for plain local file/directory copies (no tar auto-extraction or remote URL).
…jobs Fixes SonarCloud githubactions:S8233 (2 issues on auto-backport.yml:7-8). Workflow-level write permissions moved to job level following least privilege: setup-matrix gets pull-requests: read, backport keeps pull-requests:write and contents:write.
…tants Fixes SonarCloud java:S1192 (87 issues in 37 files). Behavior-identical extraction to private static final constants, reusing existing constants where Sonar suggests them. Verified with IDE inspection on all files: no errors.
…ysis Quiets secrets:S6418/S6694/S8215, yaml:S6418/S2068 and json:S6418 (31 issues) via sonar.issue.ignore.multicriteria, each rule scoped to the exact dev-only files Sonar reports (application-dev.yml, application-recette.yml, keycloak dev .env/realm, mongo dev yml). Any new secret elsewhere is still reported. Config-only change, zero runtime risk.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Instructs AI agents that Java code MUST pass mvn spotless:check (apply, do not hand-format)
b0061c1 to
6c43bf8
Compare
|







Divers correctifs liés aux rapports SonarCloud.