Skip to main content

pysonar

A Python scanner for SonarQube, available on PyPI.

Requirements

  • SonarQube v10.6 or above
  • Python 3.9 or above

Installation

Install with pip:

pip install pysonar

Usage

Once installed, the pysonar scanner can be run from the command line to perform an analysis. It assumes a running SonarQube server or a project configured on SonarCloud.

Setting up analysis properties

In order for the analysis to run, analysis properties need to be defined. There are multiple ways of providing these properties, described below in descending order of priority:

  1. Through CLI arguments to the pysonar command
  2. Environment variables for individual properties (e.g. SONAR_TOKEN, SONAR_VERBOSE, SONAR_HOST_URL, ...)
  3. Generic environment variable SONAR_SCANNER_JSON_PARAMS
  4. Under the [tool.sonar] key of the pyproject.toml file
  5. In a dedicated sonar-project.properties file
  6. Through common properties extracted from the pyproject.toml

Through CLI arguments

Analysis properties can be provided as CLI arguments to the pysonar command. They can be provided in a similar way as when running the SonarScanner CLI directly (see documentation). This means that analysis properties provided that way should be prepended with -D, for instance:

$ pysonar -Dsonar.token=myAuthenticationToken 

You can use all the arguments allowed by SonarScanner. For more information on SonarScanner please refer to the SonarScanner documentation.

Additionally, some common properties can be provided using a shorter alias, such as:

pysonar --token "MyToken"

See CLI_ARGS for more details.

With a pyproject.toml file

Inside a pyproject.toml, Sonar analysis properties can be defined under the tool.sonar table.

[tool.sonar]
# must be unique in a given SonarQube/SonarCloud instance
projectKey=my:project

# --- optional properties ---
# defaults to project key
#projectName=My project
# defaults to 'not provided'
#projectVersion=1.0
 
# Path is relative to the pyproject.toml file. Defaults to .
#sources=.
 
# Encoding of the source code. Default is default system encoding
#sourceEncoding=UTF-8

The configuration parameters can be found in the SonarQube documentation.

In the pyproject.toml file the prefix sonar. for parameter keys should be omitted. For example, sonar.scm.provider in the documentation will become scm.provider in the pyproject.toml file.

Properties in pyproject.toml files are expected to be provided in camel case. However, kebab case is also accepted:

[tool.sonar]
project-key=My Project key # valid alias for projectKey

By default, the scanner will expect the pyproject.toml file to be present in the current directory. However, its path can be provided manually through the toml-path CLI argument as well as through the sonar.projectBaseDir argument. The --toml-path argument accepts either the path to the pyproject.toml file itself or to the folder containing it. For instance:

pysonar --toml-path "path/to/pyproject.toml"

Or equivalently:

pysonar --toml-path "path/to"

Or:

pysonar --sonar-project-base-dir "path/to/projectBaseDir"

Or:

pysonar -Dsonar.projectBaseDir="path/to/projectBaseDir"

Through project properties extracted from the pyproject.toml

When a pyproject.toml file is available, the scanner can deduce analysis properties from the project configuration. This is currently supported only for projects using poetry.

With a sonar-project.properties file

Exactly like SonarScanner, the analysis can also be configured with a sonar-project.properties file:

# must be unique in a given SonarQube/SonarCloud instance
sonar.projectKey=my:project

# --- optional properties ---

# defaults to project key
#sonar.projectName=My project
# defaults to 'not provided'
#sonar.projectVersion=1.0
 
# Path is relative to the sonar-project.properties file. Defaults to .
#sonar.sources=.
 
# Encoding of the source code. Default is default system encoding
#sonar.sourceEncoding=UTF-8

Through environment variables

It is also possible to configure the scanner through environment variables:

$ export SONAR_HOST_URL="http://localhost:9000"
$ pysonar 

See the SonarScanner documentation for more information.

Feedback

For feedback and issues regarding pysonar, do not hesitate to contact us through our Community.

Installation from testPyPI

To install the latest pre-released version of Sonar Scanner Python. Execute the following command:

pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ pysonar

License

Copyright 2011-2025 SonarSource.

Licensed under the GNU Lesser General Public License, Version 3.0

Release files for pysonar 1.8.0.5390

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pysonar 1.8.0.5390
File Size Uploaded
pysonar-1.8.0.5390.tar.gz 31.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pysonar 1.8.0.5390
File Interpreter ABI Platform
pysonar-1.8.0.5390-py3-none-any.whl Python 3 none any Details

Total release size: 77.6 kB

Release files / pysonar-1.8.0.5390.tar.gz

Download URL pysonar-1.8.0.5390.tar.gz
Size 31.2 kB
Tags Source
SHA-256 checksum
How to use checksums
bf0682906f17debf2dd43cb343882ae0826e5a5d698d24e5dc3900ee96991387
BLAKE2b-256 checksum
How to use checksums
37dd54790b66fba48693e76b3f70d566e0f31692a72c97910535dad0ee4098d9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.7

Release files / pysonar-1.8.0.5390-py3-none-any.whl

Download URL pysonar-1.8.0.5390-py3-none-any.whl
Size 46.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f4857bb2dea6ecec66a5a0699d23e58f2a2a4fe2829bf4764662ac39bd7e1c8c
BLAKE2b-256 checksum
How to use checksums
4656046f87d47ea901aab9ee4d2fb06f037d17b4dc5f2139a0dbdf7b4bb7d422
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.7
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page