From 43169a3def0f2ac15347ac697190bd3d82c29dba Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 24 Jun 2026 18:58:09 +0000 Subject: [PATCH] ci(sonar): exclude hypatia wrapper from analysis (required secrets: inherit) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The hypatia-scan.yml wrapper's only SonarCloud finding is the `secrets: inherit` Security Hotspot, which is required by hyperpolymath/standards hypatia-scan-reusable.yml — the reusable consumes HYPATIA_DISPATCH_PAT but does not declare it as a workflow_call secret, so `secrets: inherit` is the only way to pass it through (gitbot-fleet Phase 2). Add sonar-project.properties excluding the thin, SHA-pinned wrapper from analysis (it has no other code to scan). NOTE: this repo uses SonarCloud Automatic Analysis, where UI settings take precedence and file-based exclusions may not clear the Quality Gate; marking the hotspot "Safe" in the SonarCloud UI is the reliable backstop. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01AHygjxRyU3WwmXEhA9KF5L --- sonar-project.properties | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 sonar-project.properties diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 0000000..728a7ee --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,20 @@ +# // Copyright (c) Jonathan D.A. Jewell +# SPDX-License-Identifier: MPL-2.0 +# SonarCloud / SonarQube Cloud analysis configuration. +# +# Exclude the Hypatia workflow wrapper from analysis. Its only Sonar +# finding is the `secrets: inherit` Security Hotspot, and that construct +# is REQUIRED by hyperpolymath/standards hypatia-scan-reusable.yml: the +# reusable consumes ${{ secrets.HYPATIA_DISPATCH_PAT }} but does not +# declare it as a workflow_call secret, so `secrets: inherit` is the only +# way to pass it through (needed by the gitbot-fleet Phase 2 learning +# submission). The file is a thin, SHA-pinned wrapper with no other code +# to analyse, so excluding it loses no meaningful coverage. +# +# NOTE: this repo uses SonarCloud Automatic Analysis, where settings +# configured in the SonarCloud UI take precedence over this file and +# file-based exclusions do not always clear the Quality Gate. If the gate +# still reports the hotspot after this lands, mark it "Safe" on the +# SonarCloud Security Hotspots page (or deactivate the rule in the Quality +# Profile) as the reliable backstop. +sonar.exclusions=.github/workflows/hypatia-scan.yml