# SonarQube analysis config for the Android-app repo. # Consumed by the scanner in .gitea/workflows/sonarqube.yml on push to main. # The project key must match the one created in SonarQube (dashboard URL # ?id=Runic-Gateway-Android-app). sonar.projectKey=Runic-Gateway-Android-app sonar.projectName=runic gateway android app # Analysed application code. The single :app module's Kotlin sources. # SonarQube's Kotlin analyzer works on source directly, so no compiled classes # or Gradle build are required for the scan. sonar.sources=app/src/main # Local unit tests (app/src/test). Instrumented tests (app/src/androidTest) can # be added here once that source set exists. sonar.tests=app/src/test # Never analyse build output, Gradle internals, or generated code. sonar.exclusions=**/build/**,**/.gradle/**,**/generated/** sonar.sourceEncoding=UTF-8 # ── Coverage (JaCoCo) ── # sonarqube.yml runs `./gradlew testDebugUnitTest jacocoTestReport` before the scan; # that task (app/build.gradle.kts) writes this XML. Without it, Sonar reports 0% # coverage even though the JVM unit suite (app/src/test) exists. sonar.coverage.jacoco.xmlReportPaths=app/build/reports/jacoco/jacocoTestReport/jacocoTestReport.xml # Exclude from *coverage* (not from analysis — bugs/smells are still reported): code a # JVM unit test physically can't execute, so counting its lines would unfairly sink # new-code coverage. Two kinds: pure-@Composable UI (needs Robolectric/instrumented # tests), and Android-framework glue (Keystore-backed stores, foreground push service, # notifications, Hilt modules). Testable logic — ViewModels, repositories, DTOs, and # pure core/ code — stays measured. See docs/android/COVERAGE_PLAN.md §1. sonar.coverage.exclusions=\ app/src/main/java/**/ui/**/*Screen.kt,\ app/src/main/java/**/ui/**/*Screen*.kt,\ app/src/main/java/**/ui/theme/**,\ app/src/main/java/**/ui/components/**,\ app/src/main/java/**/ui/page/BlockRenderer.kt,\ app/src/main/java/**/ui/shard/ShardComponents.kt,\ app/src/main/java/**/ui/LocalAssetResolver.kt,\ app/src/main/java/**/RunicApp.kt,\ app/src/main/java/**/MainActivity.kt,\ app/src/main/java/**/*Application.kt,\ app/src/main/java/**/RunicGatewayApp.kt,\ app/src/main/java/**/di/**,\ app/src/main/java/**/core/push/PushService.kt,\ app/src/main/java/**/core/push/PushManager.kt,\ app/src/main/java/**/core/push/PushNotifier.kt,\ app/src/main/java/**/core/push/NtfyStreamClient.kt,\ app/src/main/java/**/core/auth/Encrypted*.kt # ── Optional enrichment (enable once produced in CI) ── # • Android Lint: ./gradlew lintDebug → app/build/reports/lint-results-debug.xml # sonar.androidLint.reportPaths=app/build/reports/lint-results-debug.xml # The alternative to the CLI scanner used here is the SonarQube Gradle plugin # (org.sonarqube), which auto-discovers these reports; the CLI + properties file # is used instead to keep this repo's setup identical to website/ and link/.