Skip to main content

imbi-plugin-sonarqube

SonarQube integration plugin for Imbi (Plugin Architecture v3).

The package ships a single SonarQubePlugin (slug sonarqube), discovered by the imbi-common registry's imbi_plugin_* convention scan via the module-level PLUGIN attribute. Its manifest declares:

  • a service_url integration-level option (the SonarQube base URL),
  • an api_token credential (the integration's only credential) holding a SonarQube user token, and
  • one webhook-actions capability cataloging the update_project_from_webhook action.

When a SonarQube webhook arrives at imbi-gateway and a matching WebhookRule dispatches to sonarqube#update_project_from_webhook, the handler:

  1. Reads the metric→JSONPointer mapping from WebhookRule.handler_config.
  2. Fetches /api/measures/component from SonarQube using the Integration's decrypted api_token credential and its service_url option.
  3. Patches the matched Imbi project's facts.

Configuration

Operators create a SonarQube Integration, set its service_url option, and store the SonarQube API token in the Integration's encrypted credentials.

The api_token must be a user token — created under My Account > Security in SonarQube and prefixed squ_. SonarQube's analysis tokens, sqa_ (global) and sqp_ (project), are restricted to the endpoints a scanner uses and answer 403 to every request this plugin makes, including /api/measures/component and the Project Doctor's component lookup. The restriction rides on the token type, so issuing an analysis token from an administrator account does not help. Grant the token's account Browse on the projects being read, plus Create Projects if the Project Doctor should create missing SonarQube projects.

A typical webhook rule:

Handler: sonarqube#update_project_from_webhook
Filter:  /branch/is_main==true
Config:  [
           {"metric": "coverage", "path": "/test_coverage"},
           {"metric": "ncloc",    "path": "/lines_of_code"}
         ]

Release files for imbi-plugin-sonarqube 2.23.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for imbi-plugin-sonarqube 2.23.0
File Size Uploaded
imbi_plugin_sonarqube-2.23.0.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for imbi-plugin-sonarqube 2.23.0
File Interpreter ABI Platform
imbi_plugin_sonarqube-2.23.0-py3-none-any.whl Python 3 none any Details

Total release size: 39.0 kB

Release files / imbi_plugin_sonarqube-2.23.0.tar.gz

Download URL imbi_plugin_sonarqube-2.23.0.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
df3f7650a5da51db03435ff65d416593882f79905feb28f04b8c85728f420cfc
BLAKE2b-256 checksum
How to use checksums
b7cd1bc7b09a8b3a94f855c3a7a3382c0574acdc110ee1e1d0cf40e664503332
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release files / imbi_plugin_sonarqube-2.23.0-py3-none-any.whl

Download URL imbi_plugin_sonarqube-2.23.0-py3-none-any.whl
Size 17.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fe54cc7b2b93f7bac74e63419ed98a58da65618214c35507b56e81b5457896d9
BLAKE2b-256 checksum
How to use checksums
ac05f46c33c067ca99d37ad89ab65ac10064d1d483b9b1ea7f2eaf5fdbc49c8f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release history Release notifications | RSS feed

2.36.0

2 release files

2.35.1

2 release files

2.35.0

2 release files

2.34.0

2 release files

2.33.0

2 release files

2.32.3

2 release files

2.30.0

2 release files

2.29.4

2 release files

2.29.3

2 release files

2.29.2

2 release files

2.29.1

2 release files

2.29.0

2 release files

2.28.0

2 release files

2.27.0

2 release files

2.26.2

2 release files

2.26.1

2 release files

2.26.0

2 release files

2.25.0

2 release files

2.24.0

2 release files

This release

2.23.0 This release

2 release files

2.22.0

1 release file

2.21.1

2 release files

2.21.0

2 release files

2.20.0

2 release files

2.19.0

2 release files

2.18.0

2 release files

2.17.0

2 release files

2.16.1

2 release files

2.16.0

2 release files

2.15.1

2 release files

2.15.0

2 release files

2.14.1

2 release files

2.14.0

2 release files

2.13.3

2 release files

2.13.2

2 release files

2.13.0

2 release files

2.12.2

2 release files

2.12.1

2 release files

2.11.5

2 release files

2.11.4

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.11.0

2 release files

2.9.2

2 release files

2.9.1

2 release files

2.9.0

2 release files

2.8.0

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page