Skip to main content

imbi-plugin-sonarqube

SonarQube integration plugin for Imbi (Plugin Architecture v3).

The package ships a single SonarQubePlugin (slug sonarqube), discovered by the imbi-common registry's imbi_plugin_* convention scan via the module-level PLUGIN attribute. Its manifest declares:

  • a service_url integration-level option (the SonarQube base URL),
  • an api_token credential (the integration's only credential) holding a SonarQube user token, and
  • one webhook-actions capability cataloging the update_project_from_webhook action.

When a SonarQube webhook arrives at imbi-gateway and a matching WebhookRule dispatches to sonarqube#update_project_from_webhook, the handler:

  1. Reads the metric→JSONPointer mapping from WebhookRule.handler_config.
  2. Fetches /api/measures/component from SonarQube using the Integration's decrypted api_token credential and its service_url option.
  3. Patches the matched Imbi project's facts.

Configuration

Operators create a SonarQube Integration, set its service_url option, and store the SonarQube API token in the Integration's encrypted credentials.

The api_token must be a user token — created under My Account > Security in SonarQube and prefixed squ_. SonarQube's analysis tokens, sqa_ (global) and sqp_ (project), are restricted to the endpoints a scanner uses and answer 403 to every request this plugin makes, including /api/measures/component and the Project Doctor's component lookup. The restriction rides on the token type, so issuing an analysis token from an administrator account does not help. Grant the token's account Browse on the projects being read, plus Create Projects if the Project Doctor should create missing SonarQube projects.

A typical webhook rule:

Handler: sonarqube#update_project_from_webhook
Filter:  /branch/is_main==true
Config:  [
           {"metric": "coverage", "path": "/test_coverage"},
           {"metric": "ncloc",    "path": "/lines_of_code"}
         ]

Release files for imbi-plugin-sonarqube 2.26.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for imbi-plugin-sonarqube 2.26.2
File Size Uploaded
imbi_plugin_sonarqube-2.26.2.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for imbi-plugin-sonarqube 2.26.2
File Interpreter ABI Platform
imbi_plugin_sonarqube-2.26.2-py3-none-any.whl Python 3 none any Details

Total release size: 39.0 kB

Release files / imbi_plugin_sonarqube-2.26.2.tar.gz

Download URL imbi_plugin_sonarqube-2.26.2.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
aed90b0edc65355a125677876f64eae7fb03ad60bf6d32062afb94d56013ea6c
BLAKE2b-256 checksum
How to use checksums
21fdc6844cc00937f4debf6889f1499976c53c7a6f25ef7c5b2f0653826c241b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release files / imbi_plugin_sonarqube-2.26.2-py3-none-any.whl

Download URL imbi_plugin_sonarqube-2.26.2-py3-none-any.whl
Size 17.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
234447047472de89d24564019bbd719fc60b1bbcdc5b3a15ed69df0ca4722a7a
BLAKE2b-256 checksum
How to use checksums
a9c6fe618bdafec5ab679f583f7af123f25af128be2b82532bcc334ec993ff49
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 20, 2026.

Transparency log

Release history Release notifications | RSS feed

2.36.0

2 release files

2.35.1

2 release files

2.35.0

2 release files

2.34.0

2 release files

2.33.0

2 release files

2.32.3

2 release files

2.30.0

2 release files

2.29.4

2 release files

2.29.3

2 release files

2.29.2

2 release files

2.29.1

2 release files

2.29.0

2 release files

2.28.0

2 release files

2.27.0

2 release files

This release

2.26.2 This release

2 release files

2.26.1

2 release files

2.26.0

2 release files

2.25.0

2 release files

2.24.0

2 release files

2.22.0

1 release file

2.21.1

2 release files

2.21.0

2 release files

2.20.0

2 release files

2.19.0

2 release files

2.18.0

2 release files

2.17.0

2 release files

2.16.1

2 release files

2.16.0

2 release files

2.15.1

2 release files

2.15.0

2 release files

2.14.1

2 release files

2.14.0

2 release files

2.13.3

2 release files

2.13.2

2 release files

2.13.0

2 release files

2.12.2

2 release files

2.12.1

2 release files

2.11.5

2 release files

2.11.4

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.11.0

2 release files

2.9.2

2 release files

2.9.1

2 release files

2.9.0

2 release files

2.8.0

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page