Skip to main content

imbi-plugin-sonarqube

SonarQube integration plugin for Imbi (Plugin Architecture v3).

The package ships a single SonarQubePlugin (slug sonarqube), discovered by the imbi-common registry's imbi_plugin_* convention scan via the module-level PLUGIN attribute. Its manifest declares:

  • a service_url integration-level option (the SonarQube base URL),
  • an api_token credential (the integration's only credential) holding a SonarQube user token, and
  • one webhook-actions capability cataloging the update_project_from_webhook action.

When a SonarQube webhook arrives at imbi-gateway and a matching WebhookRule dispatches to sonarqube#update_project_from_webhook, the handler:

  1. Reads the metric→JSONPointer mapping from WebhookRule.handler_config.
  2. Fetches /api/measures/component from SonarQube using the Integration's decrypted api_token credential and its service_url option.
  3. Patches the matched Imbi project's facts.

Configuration

Operators create a SonarQube Integration, set its service_url option, and store the SonarQube API token in the Integration's encrypted credentials.

The api_token must be a user token — created under My Account > Security in SonarQube and prefixed squ_. SonarQube's analysis tokens, sqa_ (global) and sqp_ (project), are restricted to the endpoints a scanner uses and answer 403 to every request this plugin makes, including /api/measures/component and the Project Doctor's component lookup. The restriction rides on the token type, so issuing an analysis token from an administrator account does not help. Grant the token's account Browse on the projects being read, plus Create Projects if the Project Doctor should create missing SonarQube projects.

A typical webhook rule:

Handler: sonarqube#update_project_from_webhook
Filter:  /branch/is_main==true
Config:  [
           {"metric": "coverage", "path": "/test_coverage"},
           {"metric": "ncloc",    "path": "/lines_of_code"}
         ]

Release files for imbi-plugin-sonarqube 2.24.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for imbi-plugin-sonarqube 2.24.0
File Size Uploaded
imbi_plugin_sonarqube-2.24.0.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for imbi-plugin-sonarqube 2.24.0
File Interpreter ABI Platform
imbi_plugin_sonarqube-2.24.0-py3-none-any.whl Python 3 none any Details

Total release size: 39.0 kB

Release files / imbi_plugin_sonarqube-2.24.0.tar.gz

Download URL imbi_plugin_sonarqube-2.24.0.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
c20d5458c06ef73f666bb23ec96ecb3a6d52c7fd669c29b96336a3c8b0f3f653
BLAKE2b-256 checksum
How to use checksums
fcdce3f3b710bcf165c7d5c912784d273b8de81bb1497d48d153aac476a5dd28
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.

Transparency log

Release files / imbi_plugin_sonarqube-2.24.0-py3-none-any.whl

Download URL imbi_plugin_sonarqube-2.24.0-py3-none-any.whl
Size 17.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a552e94bedc52b24a85d4850e16c122bafdf3b7e2c34d0ab0c785b81ed1023cc
BLAKE2b-256 checksum
How to use checksums
eba7923beb7423abb9d9fa1ba5e46c8ec65e8dbd5ea5c0fa472ba1b3fad11af0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.

Transparency log

Release history Release notifications | RSS feed

2.36.0

2 release files

2.35.1

2 release files

2.35.0

2 release files

2.34.0

2 release files

2.33.0

2 release files

2.32.3

2 release files

2.30.0

2 release files

2.29.4

2 release files

2.29.3

2 release files

2.29.2

2 release files

2.29.1

2 release files

2.29.0

2 release files

2.28.0

2 release files

2.27.0

2 release files

2.26.2

2 release files

2.26.1

2 release files

2.26.0

2 release files

2.25.0

2 release files

This release

2.24.0 This release

2 release files

2.22.0

1 release file

2.21.1

2 release files

2.21.0

2 release files

2.20.0

2 release files

2.19.0

2 release files

2.18.0

2 release files

2.17.0

2 release files

2.16.1

2 release files

2.16.0

2 release files

2.15.1

2 release files

2.15.0

2 release files

2.14.1

2 release files

2.14.0

2 release files

2.13.3

2 release files

2.13.2

2 release files

2.13.0

2 release files

2.12.2

2 release files

2.12.1

2 release files

2.11.5

2 release files

2.11.4

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.11.0

2 release files

2.9.2

2 release files

2.9.1

2 release files

2.9.0

2 release files

2.8.0

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page