apache / apache/lucenenet

Resolve SonarCloud quality gate issues

Open
#1,274 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

good-first-issue help-wanted is:task pri:low up-for-grabs
Dominant language
C#
Stars
2.4k
Forks
658
Avg merge
3d 5h
Merged PRs (30d)
9

Description

### Is there an existing issue for this?

- [x] I have searched the existing issues

### Task description

The SonarCloud quality gate issues have been failing on master for some time; we should get those resolved or suppress them as needed. The latest run shows:

Failed conditions
[16 Security Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_lucenenet&branch=master&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
[E Security Rating on New Code](https://sonarcloud.io/dashboard?id=apache_lucenenet&branch=master) (required ≥ A)
[C Reliability Rating on New Code](https://sonarcloud.io/dashboard?id=apache_lucenenet&branch=master) (required ≥ A)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Open the SonarCloud security-hotspots report and master dashboard linked in the issue; review the 16 hotspots and the new-code Security and Reliability ratings. Trace each finding to its reported code location, then address or suppress the findings as appropriate and rerun the master quality gate until the required ratings pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
ci-cd
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.