Skip to main content

imbi-plugin-sonarqube

SonarQube integration plugin for Imbi (Plugin Architecture v3).

The package ships a single SonarQubePlugin (slug sonarqube), discovered by the imbi-common registry's imbi_plugin_* convention scan via the module-level PLUGIN attribute. Its manifest declares:

  • a service_url integration-level option (the SonarQube base URL),
  • an api_token credential (the integration's only credential) holding a SonarQube user token, and
  • one webhook-actions capability cataloging the update_project_from_webhook action.

When a SonarQube webhook arrives at imbi-gateway and a matching WebhookRule dispatches to sonarqube#update_project_from_webhook, the handler:

  1. Reads the metric→JSONPointer mapping from WebhookRule.handler_config.
  2. Fetches /api/measures/component from SonarQube using the Integration's decrypted api_token credential and its service_url option.
  3. Patches the matched Imbi project's facts.

Configuration

Operators create a SonarQube Integration, set its service_url option, and store the SonarQube API token in the Integration's encrypted credentials.

The api_token must be a user token — created under My Account > Security in SonarQube and prefixed squ_. SonarQube's analysis tokens, sqa_ (global) and sqp_ (project), are restricted to the endpoints a scanner uses and answer 403 to every request this plugin makes, including /api/measures/component and the Project Doctor's component lookup. The restriction rides on the token type, so issuing an analysis token from an administrator account does not help. Grant the token's account Browse on the projects being read, plus Create Projects if the Project Doctor should create missing SonarQube projects.

A typical webhook rule:

Handler: sonarqube#update_project_from_webhook
Filter:  /branch/is_main==true
Config:  [
           {"metric": "coverage", "path": "/test_coverage"},
           {"metric": "ncloc",    "path": "/lines_of_code"}
         ]

Release files for imbi-plugin-sonarqube 2.29.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for imbi-plugin-sonarqube 2.29.0
File Size Uploaded
imbi_plugin_sonarqube-2.29.0.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for imbi-plugin-sonarqube 2.29.0
File Interpreter ABI Platform
imbi_plugin_sonarqube-2.29.0-py3-none-any.whl Python 3 none any Details

Total release size: 39.0 kB

Release files / imbi_plugin_sonarqube-2.29.0.tar.gz

Download URL imbi_plugin_sonarqube-2.29.0.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
5dd84761f5e62eeac4abcaf3baf8778d86373cc4a64af39aeb162ed3e87aff2e
BLAKE2b-256 checksum
How to use checksums
0e953af274bd22de1dcaa2d88152bb247eb3af654a798abd2d0b63e09f4e3643
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / imbi_plugin_sonarqube-2.29.0-py3-none-any.whl

Download URL imbi_plugin_sonarqube-2.29.0-py3-none-any.whl
Size 17.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1f876086d90c135dc61d2341315638da1191d680b7d0aac924cf8b5de8d743fb
BLAKE2b-256 checksum
How to use checksums
1877c2d1767fdd9c5d2a34583a37e4518244937990b9f7f4ef4a43c32d953109
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release history Release notifications | RSS feed

2.36.0

2 release files

2.35.1

2 release files

2.35.0

2 release files

2.34.0

2 release files

2.33.0

2 release files

2.32.3

2 release files

2.30.0

2 release files

2.29.4

2 release files

2.29.3

2 release files

2.29.2

2 release files

2.29.1

2 release files

This release

2.29.0 This release

2 release files

2.28.0

2 release files

2.27.0

2 release files

2.26.2

2 release files

2.26.1

2 release files

2.26.0

2 release files

2.25.0

2 release files

2.24.0

2 release files

2.22.0

1 release file

2.21.1

2 release files

2.21.0

2 release files

2.20.0

2 release files

2.19.0

2 release files

2.18.0

2 release files

2.17.0

2 release files

2.16.1

2 release files

2.16.0

2 release files

2.15.1

2 release files

2.15.0

2 release files

2.14.1

2 release files

2.14.0

2 release files

2.13.3

2 release files

2.13.2

2 release files

2.13.0

2 release files

2.12.2

2 release files

2.12.1

2 release files

2.11.5

2 release files

2.11.4

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.11.0

2 release files

2.9.2

2 release files

2.9.1

2 release files

2.9.0

2 release files

2.8.0

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page