【问题标题】:Custom SonarQube rules generated with Roslyn SDK Generator have always issue type "Code Smell"使用 Roslyn SDK 生成器生成的自定义 SonarQube 规则始终发出类型“代码气味”
【发布时间】:2017-03-30 22:38:46
【问题描述】:

我正在尝试使用 Roslyn SDK 生成器在 VisualStudio 2015 中创建自定义 SonarQube 规则。

生成器工作正常,我可以将 .jar 文件发布到 SonarQube 服务器并在日常构建中使用我的自定义规则。 现在我想将规则归类为“漏洞”,但它总是显示为“代码气味”。

我尝试了几种方法:

  1. 将 DiagnosticDescriptor 类的“Category”更改为“Security”

    private const string Category = "Security";
    
    private static DiagnosticDescriptor Rule = new DiagnosticDescriptor(DiagnosticId, Title, MessageFormat, Category, DiagnosticSeverity.Warning, isEnabledByDefault: true, description: Description);
    
    public override ImmutableArray<DiagnosticDescriptor> SupportedDiagnostics { get { return ImmutableArray.Create(Rule); } }
    
  2. 更改了生成器提供的 xml 模板,并使用新的 xml 重新生成了插件(我尝试使用“SECURITY”和“SECURITY_COMPLIANCE”代替生成的“MAINTENABILITY_COMPLIANCE”)

     <sqale xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
      <chc>
        <key>SECURITY</key>
        <chc>
          <rule-key>MyRule</rule-key>
          <prop>
            <key>remediationFunction</key>
            <txt>CONSTANT_ISSUE</txt>
          </prop>
          <prop>
            <key>offset</key>
            <txt />
            <val>15min</val>
          </prop>
        </chc>
      </chc>
    </sqale>
    

到目前为止没有任何效果。

我正在使用以下配置:

  • VS2015 更新 3
  • SonarQube v. 6.1
  • SonarLint v. 2.8
  • 使用 SonarQube.Roslyn.SDK v. 1.0 开发的自定义 C# 分析器

【问题讨论】:

    标签: c# sonarqube sonarlint roslyn-code-analysis sonarlint-vs


    【解决方案1】:

    不幸的是,显式设置类别的功能似乎尚未实现 - 请参阅 https://jira.sonarsource.com/browse/SFSRAP-48

    作为一种解决方法,您可以将标签security 添加到规则中,并且由于automatic conversion of tag into category in SonarQube,规则将被归类为Vulnerabilty。但是,SonarQube.Plugins.Roslyn.RuleGenerator 在构建 SonarQube 规则时似乎没有考虑 CustomTags 属性,而是将 newRule.Tags = diagnostic.CustomTags?.ToArray(); 添加到方法 SonarQube.Plugins.Roslyn.RuleGenerator.GetAnalyzerRules 并重建 sonarqube-roslyn-sdk 即可完成这项工作。

    【讨论】:

    • 感谢您的建议。我尝试添加自定义标签security,但似乎插件生成器在生成 SonarQube 插件时忽略了自定义标签。检查 SonarQube.Roslyn.SDK v. 1.0 中的当前实现,我实际上发现类 SonarQube.Plugins.Roslyn.RuleGenerator 在构建 SonarQube 规则时没有考虑 CustomTags 属性。在方法 SonarQube.Plugins.Roslyn.RuleGenerator.GetAnalyzerRules 中添加这行代码 newRule.Tags = diagnostic.CustomTags?.ToArray(); 并在本地重建,效果很好
    • @MarcoFranzé 不知道自定义标签会被忽略,因此更新了一个答案,以防您想接受它是正确的。
    • @tamas-sonarsource-team 请你看看这个 - 这似乎是 SDK 使用中的常见困难?
    猜你喜欢
    • 2015-03-06
    • 2018-07-03
    • 2021-01-21
    • 2011-01-01
    • 2014-10-04
    • 2012-07-15
    • 1970-01-01
    • 2019-08-31
    • 2017-03-24
    相关资源
    最近更新 更多