🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

🛠️ Sonar OpenApi (plugin) ReleaseSwaggerJavaLicense: LGPL v3

Sonar OpenApi (plugin) is a code analyzer for OpenAPI specifications, is the spiritual successor of SonarOpenApi, carrying on from the point where it left off with support of Apiaddicts community.

This repository is intended for :octocat:community use, it can be modified and adapted without commercial use. If you need a version, support or help for your enterprise or project, please contact us 📧 devrel@apiaddicts.org

💡 If you have an idea for a rule but you are not sure that everyone needs it you can implement a custom rule available only for you.

TwitterDiscordLinkedInFacebookYouTube

🙌 Join the Sonar OpenApi (plugin) Adopters list

📢 If Sonar OpenApi is part of your organization's toolkit, we kindly encourage you to include your company's name in our Adopters list. 🙏 This not only significantly boosts the project's visibility and reputation but also represents a small yet impactful way to give back to the project.

OrganizationDescription of Use / Referenc
CloudAppiApification and generation of microservices
Madrid DigitalGeneration of microservices
ApiqualityGeneration of microservices

👩🏽‍💻 Contribute to ApiAddicts

We're an inclusive and open community, welcoming you to join our effort to enhance ApiAddicts, and we're excited to prioritize tasks based on community input, inviting you to review and collaborate through our GitHub issue tracker.

Feel free to drop by and greet us on our GitHub discussion or Discord chat. You can also show your support by giving us some GitHub stars ⭐️, or by following us on Twitter, LinkedIn, and subscribing to our YouTube channel! 🚀

"Buy Me A Coffee"

⚙️ Features

  • Full compatibility with OpenAPI v2.0, v3.0.0, v3.0.1, v3.0.2, v3.0.3, v3.1.0 and v3.2.0

SonarOpenApi in action

Installing

To install the plugin, you need to compile it, then install it in your SonarQube server.

  1. Make sure you have at least JDK1.8 installed, as well as Maven 3.0.5 or later. They must be present in your PATH.
  2. In the master directory of the project, type mvn install. This will compile the project and generate the artifacts.
  3. Copy the file sonar-openapi-plugin/target/sonar-openapi-plugin-<version>.jar into directory extensions/plugins/of your SonarQube installation (you can install a local copy from here for testing).
  4. Restart your SonarQube server.

Analyzing your projects

To analyze your projects, you must first install the plugin.

Configuring sonar-scanner

Once installed, configure the analysis properties by creating the sonar-project.properties at the root of your project. Sonar-scanner will look for this file when launching the analysis. Alternatively, you can define these properties as environment variables or using the Sonar Maven plugin.

An example configuration file is provided below for reference:

# must be unique in a given SonarQube instancesonar.projectKey=test:openapi
# this is the name and version displayed in the SonarQube UI. Was mandatory prior to SonarQube 6.1.sonar.projectName=OpenAPI plugin tests
sonar.projectVersion=1.0
# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows.# This property is optional if sonar.modules is set. sonar.sources=.
# Encoding of the source code. Default is default system encodingsonar.sourceEncoding=UTF-8
# Select the language to use for analysis sonar.language=openapi

For details about how to configure SonarQube Scanner to analyze your projects, see the documentation.

Configuring the plugin

The plugin automatically scans all .yaml and .json files that are compatible with the OpenAPI spec.

Is considered to be compatible with OpenAPI v2 spec if the file contains the root key swagger and compatible with the v3 if contains openapi.

Running the analysis

  • Make sure the SonarQube server is running
  • Generate a token to authenticate to the server, or ask for one to your administrator
  • With sonar-scanner in you path, just launch the tool from the directory where you have created sonar-project.properties.
  • Make sure you specify the sonar server and token when launching the analysis

You should obtain an output similar to that:

D:\git\testSonar>sonar-scanner -Dsonar.host.url=<your Sonar server> -Dsonar.login=<authorization token>
INFO: ------------- Scan OpenAPI plugin tests
INFO: Base dir: D:\git\testSonar
INFO: Working dir: d:\git\testSonar\.sonar
INFO: Source paths: .
INFO: Source encoding: UTF-8, default locale: en_US
INFO: Load server rules
INFO: Load server rules (done) | time=229ms
INFO: Index files
INFO: 4 files indexed
INFO: Quality profile for openapi: Sonar way
INFO: Sensor SonarJavaXmlFileSensor [java]
INFO: Sensor SonarJavaXmlFileSensor [java] (done) | time=1ms
INFO: Sensor OpenAPI Scanner Sensor [openapi]
INFO: Sensor OpenAPI Scanner Sensor [openapi] (done) | time=270ms
INFO: Sensor Zero Coverage Sensor
INFO: Sensor Zero Coverage Sensor (done) | time=8ms
INFO: No SCM system was detected. You can use the 'sonar.scm.provider' property to explicitly specify it.
INFO: Calculating CPD for 6 files
INFO: CPD calculation finished
INFO: Analysis report generated in 215ms, dir size=92 KB
INFO: Analysis reports compressed in 37ms, zip size=17 KB
INFO: Analysis report uploaded in 75ms
INFO: ANALYSIS SUCCESSFUL, you can browse <your Sonar server>/dashboard?id=test%3Aopenapi
INFO: Note that you will be able to access the updated dashboard once the server has processed the submitted analysis report
INFO: More about the report processing at <your Sonar server>/api/ce/task?id=AWZZE5MdehEa_CTMQA3m
INFO: Task total time: 3.356 s
INFO: ------------------------------------------------------------------------
INFO: EXECUTION SUCCESS
INFO: ------------------------------------------------------------------------

Then, log into your SonarQube server and go to your project to see the found violations (if any).

Skipping rules

Sometimes, it makes sense to disable a rule altogether. The plugin comes with a way to control which rule is enabled on a specific file. Use it with caution as it is generally a bad practice to disable a rule from code!

The x-nosonar OpenAPI extension completely disables a rule. Add it to the top-level OpenAPI document to disable a rule or a set of rules:

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]

You can pass either a string or an array of string to the extension.

To disable a rule only in a specific API element, use the x-sonar-disable extension. To enable an otherwise globally disable rule, use the x-sonar-enable extension. They are recognized in any API element that supports extensions, except on the top-level document.

openapi: "3.0.0"info:
version: 1.0.0title: Swagger Petstorelicense:
name: MITservers:
- url: http://petstore.swagger.io/v1x-nosonar: [ RuleId1, RuleId2 ]paths:
/pets:
get:
# This re-enables RuleId1 in this operation only (it is not inherited by child elements like tags or parameters)x-sonar-enable: RuleId1summary: List all petsoperationId: listPetstags:
- petsparameters:
- name: filterin: querydescription: attribute on which to filterrequired: falseschema:
type: string# This disables RuleId3 locally in this parameter (it is not inherited by child elements like schema)x-sonar-disable: RuleId3

As for x-nosonar, the x-sonar-disable and x-sonar-enable extensions accept a single string or an array of strings.

Testing

To run tests locally follow these instructions.

Build the Project and Run Unit Tests

To build the plugin and run its unit tests, execute this command from the project's root directory:

mvn clean install

Integration Tests

Integration tests are provided with the plugin. To include them, use the "its" profile:

mvn -Pits clean install

If you are running behind an enterprise proxy, specify the java proxy options on the command line:

  • http.proxyHost
  • http.proxyPort
  • http.proxyUser
  • http.proxyPassword
  • https.proxyHost
  • https.proxyPort
  • https.proxyUser
  • https.proxyPassword

Performing a new release

Validate that all is correct:

mvn clean package -Prelease

Deploy:

mvn clean deploy -Prelease

💛 Sponsors

cloudappimd

About

Evaluation engine for OpenAPI/Swagger API definitions in SonarQube

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages