Skip to main content

imbi-plugin-sonarqube

SonarQube integration plugin for Imbi (Plugin Architecture v3).

The package ships a single SonarQubePlugin (slug sonarqube), discovered by the imbi-common registry's imbi_plugin_* convention scan via the module-level PLUGIN attribute. Its manifest declares:

  • a service_url integration-level option (the SonarQube base URL),
  • an api_token credential (the integration's only credential) holding a SonarQube user token, and
  • one webhook-actions capability cataloging the update_project_from_webhook action.

When a SonarQube webhook arrives at imbi-gateway and a matching WebhookRule dispatches to sonarqube#update_project_from_webhook, the handler:

  1. Reads the metric→JSONPointer mapping from WebhookRule.handler_config.
  2. Fetches /api/measures/component from SonarQube using the Integration's decrypted api_token credential and its service_url option.
  3. Patches the matched Imbi project's facts.

Configuration

Operators create a SonarQube Integration, set its service_url option, and store the SonarQube API token in the Integration's encrypted credentials.

The api_token must be a user token — created under My Account > Security in SonarQube and prefixed squ_. SonarQube's analysis tokens, sqa_ (global) and sqp_ (project), are restricted to the endpoints a scanner uses and answer 403 to every request this plugin makes, including /api/measures/component and the Project Doctor's component lookup. The restriction rides on the token type, so issuing an analysis token from an administrator account does not help. Grant the token's account Browse on the projects being read, plus Create Projects if the Project Doctor should create missing SonarQube projects.

A typical webhook rule:

Handler: sonarqube#update_project_from_webhook
Filter:  /branch/is_main==true
Config:  [
           {"metric": "coverage", "path": "/test_coverage"},
           {"metric": "ncloc",    "path": "/lines_of_code"}
         ]

Release files for imbi-plugin-sonarqube 2.33.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for imbi-plugin-sonarqube 2.33.0
File Size Uploaded
imbi_plugin_sonarqube-2.33.0.tar.gz 21.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for imbi-plugin-sonarqube 2.33.0
File Interpreter ABI Platform
imbi_plugin_sonarqube-2.33.0-py3-none-any.whl Python 3 none any Details

Total release size: 40.0 kB

Release files / imbi_plugin_sonarqube-2.33.0.tar.gz

Download URL imbi_plugin_sonarqube-2.33.0.tar.gz
Size 21.9 kB
Tags Source
SHA-256 checksum
How to use checksums
b5ad0b9a45d04ed7a937d738e347e950d3175a985f7f0cf8d02fb94de896785f
BLAKE2b-256 checksum
How to use checksums
e95c900cbec814f105c637b0dc9b10a2e3730a2b2f99cecd922c68d3905c5a9a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release files / imbi_plugin_sonarqube-2.33.0-py3-none-any.whl

Download URL imbi_plugin_sonarqube-2.33.0-py3-none-any.whl
Size 18.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
55e171f19d2661a71fb69ec01e3df20c5d7f2266858faa18b0e090948ee741f5
BLAKE2b-256 checksum
How to use checksums
daf6a7a46dc292d8ef88062d242530e269aa9fc500b45492fde1313385772651
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.

Transparency log

Release history Release notifications | RSS feed

2.36.0

2 release files

2.35.1

2 release files

2.35.0

2 release files

2.34.0

2 release files

This release

2.33.0 This release

2 release files

2.32.3

2 release files

2.30.0

2 release files

2.29.4

2 release files

2.29.3

2 release files

2.29.2

2 release files

2.29.1

2 release files

2.29.0

2 release files

2.28.0

2 release files

2.27.0

2 release files

2.26.2

2 release files

2.26.1

2 release files

2.26.0

2 release files

2.25.0

2 release files

2.24.0

2 release files

2.22.0

1 release file

2.21.1

2 release files

2.21.0

2 release files

2.20.0

2 release files

2.19.0

2 release files

2.18.0

2 release files

2.17.0

2 release files

2.16.1

2 release files

2.16.0

2 release files

2.15.1

2 release files

2.15.0

2 release files

2.14.1

2 release files

2.14.0

2 release files

2.13.3

2 release files

2.13.2

2 release files

2.13.0

2 release files

2.12.2

2 release files

2.12.1

2 release files

2.11.5

2 release files

2.11.4

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.11.0

2 release files

2.9.2

2 release files

2.9.1

2 release files

2.9.0

2 release files

2.8.0

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page