Repository navigation
refactor(all-services): resolve sonarcloud quality gate failures - #131
Merged
Merged
Conversation
Fix the SonarCloud issues that gate the build on master, without suppressing anything via NOSONAR or blanket eslint-disable comments. release.yml (githubactions:S6505, S8543) - run lerna through `npx --ignore-scripts lerna@9.0.7` on both the version and publish steps, so lifecycle scripts cannot run and the version resolved matches the lockfile tenant-management-service - name the suppressed rule on 15 bare eslint-disable-next-line comments in the auth0 and keycloak idp providers (typescript:S7724) - import crypto via the node: protocol (typescript:S7772) - use Number.isNaN over the global isNaN (typescript:S7773) - use String.fromCodePoint over String.fromCharCode (typescript:S7758) - replace two && guard chains with optional chaining (typescript:S6582) - extract the lead address mismatch guard out of OnboardingService.onboard to bring its cyclomatic complexity under the limit (typescript:S1541) Dockerfiles - accept the docker:S8482, S6506, S6505 and S8543 findings on the tenant-management and subscription service Dockerfiles and exclude both files in .sonarcloud.properties; container scanning stays covered by the existing trivy workflow Lint, build and tests pass in all three services. GH-130
|
piyushsinghgaur1
requested review from
a-ganguly,
rohit-sourcefuse and
yeshamavani
September 9, 2026 07:50
yeshamavani
approved these changes
Sep 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
Resolves the failing SonarCloud quality gate on
master(projectsourcefuse_arc-saas). The gate was red on 7 of its 14 conditions, with 65 open issues including 2 BLOCKERs, 1 CRITICAL and 12 vulnerabilities.Every code finding gets its real remediation — nothing is suppressed with
// NOSONARor a new blanketeslint-disable.Fixes #130
.github/workflows/release.yml— 4 vulnerabilitiesgithubactions:S6505,githubactions:S8543on the Bump Versions and Publish steps.Both now run
npx --ignore-scripts lerna@9.0.7 …. This matches the rule's documented compliant form exactly —--ignore-scriptsbefore the package name blocks lifecycle scripts, and the exact version pin (matchingpackage-lock.json) prevents an unverified release being resolved at runtime.tenant-management-service— 23 issuestypescript:S7724eslint-disable-next-linecomments now name the rule they suppress (@typescript-eslint/naming-convention, confirmed by runningeslint --no-inline-config). Lint still passes with--report-unused-disable-directives, so every directive remains load-bearing.typescript:S7772crypto→node:cryptotypescript:S6582&&guard chains → optional chainingtypescript:S7758String.fromCharCode→String.fromCodePoint(arguments are ASCII 32–126, so full code points)typescript:S7773isNaN→Number.isNaN(the value is alreadyNumber(...)-coerced, so behaviour is identical)typescript:S1541OnboardingService.onboardinto_assertAddressMatchesLead. Pure refactor, no behaviour change.Dockerfiles — analysis exclusion
docker:S8482×2 (BLOCKER),docker:S6506×2,docker:S6505×2,docker:S8543×2 are raised against the tenant-management and subscription Dockerfiles.Both files are added to
sonar.exclusionsin.sonarcloud.properties, so the Dockerfiles themselves are unchanged — thenode-pruneinstall and thenpm installstep stay as they are. Container scanning is already covered by the existing Trivy workflow.The two paths are listed explicitly rather than as
**/Dockerfile, so a Dockerfile added for a future service is still analysed rather than silently inheriting the exclusion.services/orchestrator-service/openapi.{json,md}Regenerated by
npm run build; picks up a stale1.3.0→1.3.1version string.Type of change
How Has This Been Tested?
npm run build— exit 0 across all workspacesnpm run lint --workspaces— exit 0 (eslint + prettier)npm test— exit 0, 116 passing (76 tenant-management, 36 subscription, 4 orchestrator)onboardmeasured independently with ESLint'scomplexityrule: 12 → 7, with the extracted helper at 6. Sonar counts slightly differently — it reported 11 — but both halves are now well under the limit of 10.Projected gate
blocker_violationscritical_violationsmajor_violationsnew_major_violationsnew_vulnerabilitiessecurity_ratingnew_security_ratingThis is a projection from the last analysis snapshot combined with the official rule definitions. SonarCloud's server-side analysis returns 403 for this organization via the CLI (
Vortex Analysis is not available for this organization), so it could not be checked against the real analyzer beforehand. The margin onmajor_violationsis 3.Checklist: