From 738a30c883afbf2c4be1867ca77520d61599736e Mon Sep 17 00:00:00 2001 From: Guillaume Dequenne Date: Mon, 28 Sep 2026 17:24:20 +0200 Subject: [PATCH 1/9] CLP-918 Migrate Orchestrator downloads to JFrog Edge --- .github/workflows/build.yml | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 7eb05de8a26..754d596b4a5 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -108,6 +108,10 @@ jobs: uses: ./.github/actions/orchestrator-cache with: sq-version: ${{ matrix.item.sq_version }} + - name: Wait for Artifactory token federation + uses: SonarSource/sonarsource-infra-artifactory/.github/actions/wait-for-artifactory-token-federation@979fc5f122d4f67f0d7e0ea880e0f1c3b8019941 + with: + probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Run ruling tests shell: bash # Set explicitly so Bash is used on Windows runners too. env: @@ -121,7 +125,7 @@ jobs: if [[ "${RUNNER_OS}" != "Windows" ]]; then extra_args+=(-Dparallel=methods -DuseUnlimitedThreads=true) fi - mvn package ${MAVEN_OUTPUT_ARGS} "-Pit-ruling,${{ matrix.item.profile }}" -Dsonar.runtimeVersion=${{ matrix.item.sq_version }} -Dmaven.test.redirectTestOutputToFile=false "${extra_args[@]}" + mvn package ${MAVEN_OUTPUT_ARGS} "-Pit-ruling,${{ matrix.item.profile }}" -Dsonar.runtimeVersion=${{ matrix.item.sq_version }} -Dorchestrator.artifactory.url=https://repox-internal.dev.sonar.build/artifactory "-Dorchestrator.artifactory.accessToken=${ARTIFACTORY_ACCESS_TOKEN}" -Dmaven.test.redirectTestOutputToFile=false "${extra_args[@]}" - name: Upload Actual Results On Failure if: failure() uses: ./.github/actions/upload-actual @@ -228,12 +232,16 @@ jobs: uses: ./.github/actions/orchestrator-cache with: sq-version: ${{ matrix.sq_version }} + - name: Wait for Artifactory token federation + uses: SonarSource/sonarsource-infra-artifactory/.github/actions/wait-for-artifactory-token-federation@979fc5f122d4f67f0d7e0ea880e0f1c3b8019941 + with: + probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Plugin QA env: GITHUB_TOKEN: ${{ fromJSON(steps.secrets.outputs.vault).GITHUB_TOKEN }} run: | cd its/plugin - mvn package ${MAVEN_OUTPUT_ARGS} -Pit-plugin -Dsonar.runtimeVersion=${{ matrix.sq_version }} -Dmaven.test.redirectTestOutputToFile=false -Dparallel=classes -DuseUnlimitedThreads=true + mvn package ${MAVEN_OUTPUT_ARGS} -Pit-plugin -Dsonar.runtimeVersion=${{ matrix.sq_version }} -Dorchestrator.artifactory.url=https://repox-internal.dev.sonar.build/artifactory "-Dorchestrator.artifactory.accessToken=${ARTIFACTORY_ACCESS_TOKEN}" -Dmaven.test.redirectTestOutputToFile=false -Dparallel=classes -DuseUnlimitedThreads=true sanity: name: Sanity Test From c7fa53c5bf15a8526586e48f4cd03715a86156f5 Mon Sep 17 00:00:00 2001 From: Guillaume Dequenne Date: Tue, 29 Sep 2026 09:20:17 +0200 Subject: [PATCH 2/9] CLP-918 Keep Edge token wait action in repository --- .../action.yml | 39 +++++++++++++++++++ .github/workflows/build.yml | 4 +- 2 files changed, 41 insertions(+), 2 deletions(-) create mode 100644 .github/actions/wait-for-artifactory-token-federation/action.yml diff --git a/.github/actions/wait-for-artifactory-token-federation/action.yml b/.github/actions/wait-for-artifactory-token-federation/action.yml new file mode 100644 index 00000000000..241340e6a5d --- /dev/null +++ b/.github/actions/wait-for-artifactory-token-federation/action.yml @@ -0,0 +1,39 @@ +name: Wait for Artifactory token federation +description: Wait until a Vault-issued Artifactory token is accepted by the JFrog Edge node + +inputs: + artifactory-url: + description: JFrog Artifactory base URL + default: https://repox-internal.dev.sonar.build/artifactory + probe-path: + description: Authenticated Edge endpoint path and optional query used to verify the token + required: true + +runs: + using: composite + steps: + - shell: bash + env: + ARTIFACTORY_URL: ${{ inputs.artifactory-url }} + PROBE_PATH: ${{ inputs.probe-path }} + run: | + : "${ARTIFACTORY_ACCESS_TOKEN:?ARTIFACTORY_ACCESS_TOKEN must be configured before waiting for token federation}" + + for attempt in {1..12}; do + status=$(curl --silent --output /dev/null --write-out "%{http_code}" \ + --header "Authorization: Bearer ${ARTIFACTORY_ACCESS_TOKEN}" \ + "${ARTIFACTORY_URL}/${PROBE_PATH}" || true) + if [[ "${status}" == "200" ]]; then + echo "Artifactory token accepted by Edge" + exit 0 + fi + if [[ "${status}" != "401" && "${status}" != "000" ]]; then + echo "Unexpected response from Edge: HTTP ${status}" + exit 1 + fi + echo "Waiting for Artifactory token federation (attempt ${attempt}/12)" + sleep 10 + done + + echo "Artifactory token was not accepted by Edge within 2 minutes" + exit 1 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 754d596b4a5..e9ba8bd0660 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -109,7 +109,7 @@ jobs: with: sq-version: ${{ matrix.item.sq_version }} - name: Wait for Artifactory token federation - uses: SonarSource/sonarsource-infra-artifactory/.github/actions/wait-for-artifactory-token-federation@979fc5f122d4f67f0d7e0ea880e0f1c3b8019941 + uses: ./.github/actions/wait-for-artifactory-token-federation with: probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Run ruling tests @@ -233,7 +233,7 @@ jobs: with: sq-version: ${{ matrix.sq_version }} - name: Wait for Artifactory token federation - uses: SonarSource/sonarsource-infra-artifactory/.github/actions/wait-for-artifactory-token-federation@979fc5f122d4f67f0d7e0ea880e0f1c3b8019941 + uses: ./.github/actions/wait-for-artifactory-token-federation with: probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Plugin QA From 952fc9b35156658634641fe92d275c5823772e77 Mon Sep 17 00:00:00 2001 From: Guillaume Dequenne Date: Tue, 29 Sep 2026 10:06:12 +0200 Subject: [PATCH 3/9] CLP-918 Report Edge probe response and bound connection time --- .../actions/wait-for-artifactory-token-federation/action.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/actions/wait-for-artifactory-token-federation/action.yml b/.github/actions/wait-for-artifactory-token-federation/action.yml index 241340e6a5d..bd3b298f211 100644 --- a/.github/actions/wait-for-artifactory-token-federation/action.yml +++ b/.github/actions/wait-for-artifactory-token-federation/action.yml @@ -20,7 +20,7 @@ runs: : "${ARTIFACTORY_ACCESS_TOKEN:?ARTIFACTORY_ACCESS_TOKEN must be configured before waiting for token federation}" for attempt in {1..12}; do - status=$(curl --silent --output /dev/null --write-out "%{http_code}" \ + status=$(curl --silent --show-error --connect-timeout 5 --max-time 10 --output /dev/null --write-out "%{http_code}" \ --header "Authorization: Bearer ${ARTIFACTORY_ACCESS_TOKEN}" \ "${ARTIFACTORY_URL}/${PROBE_PATH}" || true) if [[ "${status}" == "200" ]]; then @@ -31,7 +31,7 @@ runs: echo "Unexpected response from Edge: HTTP ${status}" exit 1 fi - echo "Waiting for Artifactory token federation (attempt ${attempt}/12)" + echo "Waiting for Artifactory token federation (attempt ${attempt}/12, HTTP ${status})" sleep 10 done From 4d74630b514c4cdc6a1e2c6280b07f65e461d326 Mon Sep 17 00:00:00 2001 From: Guillaume Dequenne Date: Tue, 29 Sep 2026 10:24:16 +0200 Subject: [PATCH 4/9] CLP-918 Retry transient Edge responses during token wait --- .../actions/wait-for-artifactory-token-federation/action.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/actions/wait-for-artifactory-token-federation/action.yml b/.github/actions/wait-for-artifactory-token-federation/action.yml index bd3b298f211..d1e85f70c13 100644 --- a/.github/actions/wait-for-artifactory-token-federation/action.yml +++ b/.github/actions/wait-for-artifactory-token-federation/action.yml @@ -27,7 +27,7 @@ runs: echo "Artifactory token accepted by Edge" exit 0 fi - if [[ "${status}" != "401" && "${status}" != "000" ]]; then + if [[ ! "${status}" =~ ^(000|401|408|429|500|502|503|504)$ ]]; then echo "Unexpected response from Edge: HTTP ${status}" exit 1 fi From 156d231afde21dd2711a1002eeb3c9218f1e014c Mon Sep 17 00:00:00 2001 From: Guillaume Dequenne Date: Tue, 29 Sep 2026 10:39:24 +0200 Subject: [PATCH 5/9] CLP-918 Use shared Edge token federation action --- .../action.yml | 39 ------------------- .github/workflows/build.yml | 4 +- 2 files changed, 2 insertions(+), 41 deletions(-) delete mode 100644 .github/actions/wait-for-artifactory-token-federation/action.yml diff --git a/.github/actions/wait-for-artifactory-token-federation/action.yml b/.github/actions/wait-for-artifactory-token-federation/action.yml deleted file mode 100644 index d1e85f70c13..00000000000 --- a/.github/actions/wait-for-artifactory-token-federation/action.yml +++ /dev/null @@ -1,39 +0,0 @@ -name: Wait for Artifactory token federation -description: Wait until a Vault-issued Artifactory token is accepted by the JFrog Edge node - -inputs: - artifactory-url: - description: JFrog Artifactory base URL - default: https://repox-internal.dev.sonar.build/artifactory - probe-path: - description: Authenticated Edge endpoint path and optional query used to verify the token - required: true - -runs: - using: composite - steps: - - shell: bash - env: - ARTIFACTORY_URL: ${{ inputs.artifactory-url }} - PROBE_PATH: ${{ inputs.probe-path }} - run: | - : "${ARTIFACTORY_ACCESS_TOKEN:?ARTIFACTORY_ACCESS_TOKEN must be configured before waiting for token federation}" - - for attempt in {1..12}; do - status=$(curl --silent --show-error --connect-timeout 5 --max-time 10 --output /dev/null --write-out "%{http_code}" \ - --header "Authorization: Bearer ${ARTIFACTORY_ACCESS_TOKEN}" \ - "${ARTIFACTORY_URL}/${PROBE_PATH}" || true) - if [[ "${status}" == "200" ]]; then - echo "Artifactory token accepted by Edge" - exit 0 - fi - if [[ ! "${status}" =~ ^(000|401|408|429|500|502|503|504)$ ]]; then - echo "Unexpected response from Edge: HTTP ${status}" - exit 1 - fi - echo "Waiting for Artifactory token federation (attempt ${attempt}/12, HTTP ${status})" - sleep 10 - done - - echo "Artifactory token was not accepted by Edge within 2 minutes" - exit 1 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e9ba8bd0660..877ee916fb5 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -109,7 +109,7 @@ jobs: with: sq-version: ${{ matrix.item.sq_version }} - name: Wait for Artifactory token federation - uses: ./.github/actions/wait-for-artifactory-token-federation + uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4 with: probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Run ruling tests @@ -233,7 +233,7 @@ jobs: with: sq-version: ${{ matrix.sq_version }} - name: Wait for Artifactory token federation - uses: ./.github/actions/wait-for-artifactory-token-federation + uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4 with: probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Plugin QA From dca453857504080ec762163d339388f946e24f22 Mon Sep 17 00:00:00 2001 From: Hedi Nasr Date: Fri, 2 Oct 2026 10:08:43 +0200 Subject: [PATCH 6/9] BUILD-12160 Resolve through the JFrog Edge with Edge-issued tokens --- .github/workflows/build.yml | 35 +++++++++++++++++------------------ 1 file changed, 17 insertions(+), 18 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 7f908cb5559..851ced30157 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -34,11 +34,12 @@ jobs: - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 with: version: 2026.9.14 - - uses: SonarSource/ci-github-actions/build-maven@v2 + - uses: SonarSource/ci-github-actions/build-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 id: build-maven env: MAVEN_OPTS: "-Xmx8g" with: + repox-url: https://repox-internal.dev.sonar.build deploy-pull-request: true sonar-platform: none # Prevent analysis # Override artifactory roles for public repo using private access @@ -91,8 +92,9 @@ jobs: with: namespace: ruling-qa-${{ matrix.item.runner }}-${{ matrix.item.profile }}-${{ matrix.item.sq_version }} - name: Configure Maven - uses: SonarSource/ci-github-actions/config-maven@v2 + uses: SonarSource/ci-github-actions/config-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build artifactory-reader-role: private-reader use-develocity: ${{ env.USE_DEVELOCITY }} develocity-url: ${{ env.DEVELOCITY_URL }} @@ -107,10 +109,6 @@ jobs: uses: ./.github/actions/orchestrator-cache with: sq-version: ${{ matrix.item.sq_version }} - - name: Wait for Artifactory token federation - uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4 - with: - probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Run ruling tests shell: bash # Set explicitly so Bash is used on Windows runners too. env: @@ -124,7 +122,7 @@ jobs: if [[ "${RUNNER_OS}" != "Windows" ]]; then extra_args+=(-Dparallel=methods -DuseUnlimitedThreads=true) fi - mvn package ${MAVEN_OUTPUT_ARGS} "-Pit-ruling,${{ matrix.item.profile }}" -Dsonar.runtimeVersion=${{ matrix.item.sq_version }} -Dorchestrator.artifactory.url=https://repox-internal.dev.sonar.build/artifactory "-Dorchestrator.artifactory.accessToken=${ARTIFACTORY_ACCESS_TOKEN}" -Dmaven.test.redirectTestOutputToFile=false "${extra_args[@]}" + mvn package ${MAVEN_OUTPUT_ARGS} "-Pit-ruling,${{ matrix.item.profile }}" -Dsonar.runtimeVersion=${{ matrix.item.sq_version }} -Dmaven.test.redirectTestOutputToFile=false "${extra_args[@]}" - name: Upload Actual Results On Failure if: failure() uses: ./.github/actions/upload-actual @@ -214,8 +212,9 @@ jobs: with: namespace: plugin-qa-${{ matrix.sq_version }} - name: Configure Maven - uses: SonarSource/ci-github-actions/config-maven@v2 + uses: SonarSource/ci-github-actions/config-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build artifactory-reader-role: private-reader use-develocity: ${{ env.USE_DEVELOCITY }} develocity-url: ${{ env.DEVELOCITY_URL }} @@ -230,16 +229,12 @@ jobs: uses: ./.github/actions/orchestrator-cache with: sq-version: ${{ matrix.sq_version }} - - name: Wait for Artifactory token federation - uses: SonarSource/ci-github-actions/wait-for-artifactory-token-federation@715009ff183f509d685a028c3cac34c69e3714c4 - with: - probe-path: "api/search/versions?g=com.sonarsource.sonarqube&a=sonarqube-enterprise-lw&remote=1&repos=sonarsource-releases&v=*" - name: Plugin QA env: GITHUB_TOKEN: ${{ fromJSON(steps.secrets.outputs.vault).GITHUB_TOKEN }} run: | cd its/plugin - mvn package ${MAVEN_OUTPUT_ARGS} -Pit-plugin -Dsonar.runtimeVersion=${{ matrix.sq_version }} -Dorchestrator.artifactory.url=https://repox-internal.dev.sonar.build/artifactory "-Dorchestrator.artifactory.accessToken=${ARTIFACTORY_ACCESS_TOKEN}" -Dmaven.test.redirectTestOutputToFile=false -Dparallel=classes -DuseUnlimitedThreads=true + mvn package ${MAVEN_OUTPUT_ARGS} -Pit-plugin -Dsonar.runtimeVersion=${{ matrix.sq_version }} -Dmaven.test.redirectTestOutputToFile=false -Dparallel=classes -DuseUnlimitedThreads=true sanity: name: Sanity Test @@ -266,8 +261,9 @@ jobs: - uses: ./.github/actions/maven-cache with: namespace: sanity - - uses: SonarSource/ci-github-actions/config-maven@v2 + - uses: SonarSource/ci-github-actions/config-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build artifactory-reader-role: private-reader use-develocity: ${{ env.USE_DEVELOCITY }} develocity-url: ${{ env.DEVELOCITY_URL }} @@ -309,8 +305,9 @@ jobs: secrets: | development/kv/data/next url | SONAR_HOST_URL; development/kv/data/next token | SONAR_TOKEN; - - uses: SonarSource/ci-github-actions/build-maven@v2 + - uses: SonarSource/ci-github-actions/build-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build deploy: false artifactory-reader-role: private-reader # Override default public-reader artifactory-deployer-role: qa-deployer # Override default public-deployer @@ -348,8 +345,9 @@ jobs: - uses: ./.github/actions/maven-cache with: namespace: custom-rules-license-check - - uses: SonarSource/ci-github-actions/config-maven@v2 + - uses: SonarSource/ci-github-actions/config-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build artifactory-reader-role: private-reader use-develocity: ${{ env.USE_DEVELOCITY }} develocity-url: ${{ env.DEVELOCITY_URL }} @@ -392,8 +390,9 @@ jobs: with: namespace: qa-os-win - name: Configure Maven - uses: SonarSource/ci-github-actions/config-maven@v2 + uses: SonarSource/ci-github-actions/config-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: + repox-url: https://repox-internal.dev.sonar.build artifactory-reader-role: private-reader use-develocity: ${{ env.USE_DEVELOCITY }} develocity-url: ${{ env.DEVELOCITY_URL }} @@ -422,7 +421,7 @@ jobs: env: BUILD_NUMBER: ${{ needs.build.outputs.build-number }} steps: - - uses: SonarSource/ci-github-actions/promote@v2 + - uses: SonarSource/ci-github-actions/promote@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 with: promote-pull-request: true From 706126f9eab667529a27ca2db98b6fda21eb0a9d Mon Sep 17 00:00:00 2001 From: Hedi Nasr Date: Fri, 2 Oct 2026 11:10:42 +0200 Subject: [PATCH 7/9] BUILD-12160 Use Orchestrator 6.4.3 locators in the scanner integration tests sonar-scanner-integration-tester 1.2.0.1354 brings Orchestrator 6.2.0, which treats an Edge ARTIFACTORY_URL as a plain Maven repository and reads its maven-metadata.xml without a token. Orchestrator 6.4.3 authenticates on the Edge. Also resolve the dogfooding build through the Edge with the 2.2.0 pin. --- .github/workflows/unified-dogfooding.yml | 3 ++- its/scanner-integration-tests/pom.xml | 15 +++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/.github/workflows/unified-dogfooding.yml b/.github/workflows/unified-dogfooding.yml index 108b54a130b..c07993c2f1f 100644 --- a/.github/workflows/unified-dogfooding.yml +++ b/.github/workflows/unified-dogfooding.yml @@ -16,11 +16,12 @@ jobs: - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 with: version: 2026.9.14 - - uses: SonarSource/ci-github-actions/build-maven@v2 + - uses: SonarSource/ci-github-actions/build-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0 env: MAVEN_OPTS: "-Xmx8g" JAVA_TOOL_OPTIONS: "" with: + repox-url: https://repox-internal.dev.sonar.build run-shadow-scans: true artifactory-reader-role: private-reader artifactory-deployer-role: qa-deployer diff --git a/its/scanner-integration-tests/pom.xml b/its/scanner-integration-tests/pom.xml index fdac2bd838b..16ef2b841fe 100644 --- a/its/scanner-integration-tests/pom.xml +++ b/its/scanner-integration-tests/pom.xml @@ -18,6 +18,21 @@ false + + + + org.sonarsource.orchestrator + sonar-orchestrator-locators + ${orchestrator.version} + + + org.sonarsource.orchestrator + sonar-orchestrator-build + ${orchestrator.version} + + + + com.sonarsource.scanner.integrationtester From 7976ab535216929ce41bbe36e7387c11c61f65c2 Mon Sep 17 00:00:00 2001 From: Hedi Nasr Date: Fri, 2 Oct 2026 11:26:58 +0200 Subject: [PATCH 8/9] BUILD-12160 Drop the ineffective Orchestrator locators override sonar-scanner-integration-tester is a shaded jar that bundles its Orchestrator classes and declares no Orchestrator dependency, so dependencyManagement cannot change the version it runs. The scanner integration tests need a tester release built with Orchestrator 6.4.3. --- its/scanner-integration-tests/pom.xml | 15 --------------- 1 file changed, 15 deletions(-) diff --git a/its/scanner-integration-tests/pom.xml b/its/scanner-integration-tests/pom.xml index 16ef2b841fe..fdac2bd838b 100644 --- a/its/scanner-integration-tests/pom.xml +++ b/its/scanner-integration-tests/pom.xml @@ -18,21 +18,6 @@ false - - - - org.sonarsource.orchestrator - sonar-orchestrator-locators - ${orchestrator.version} - - - org.sonarsource.orchestrator - sonar-orchestrator-build - ${orchestrator.version} - - - - com.sonarsource.scanner.integrationtester From e92a8b1efc4fb41b1ed8be72a495ad6fc01f9faf Mon Sep 17 00:00:00 2001 From: Hedi Nasr Date: Fri, 2 Oct 2026 14:06:14 +0200 Subject: [PATCH 9/9] BUILD-12160 Upgrade sonar-scanner-integration-tester to 1.3.0.1396 sonar-scanner-integration-tester 1.3.0.1396 bundles Orchestrator 6.4.3, which authenticates on the JFrog Edge. 1.2.0.1354 bundled Orchestrator 6.2.0, which read maven-metadata.xml from the Edge without a token. --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 5d2ed8261e5..e5da5dae7c9 100644 --- a/pom.xml +++ b/pom.xml @@ -96,7 +96,7 @@ its/**,java-checks-test-sources/** 2.33.0.5369 6.4.3.4676 - 1.2.0.1354 + 1.3.0.1396 1.26.0.4194 -Xmx512m sonar-java