# SonarQube analysis config for module-uo. # Consumed by the scanner in .gitea/workflows/sonarqube.yml on push to main. # The project key must match the one created in SonarQube (dashboard URL # ?id=Module-uo). sonar.projectKey=Module-uo sonar.projectName=Module-uo # Analysed application code. # # Unlike core's repo there is no `src/` directory to point at: the server half # keeps its code at `server/` root (boot.js, core.js, index.js) beside its # subdirectories, so the whole tree is included and the non-source parts are # excluded below. That direction is deliberate — a new top-level server # directory is scanned by default rather than silently unscanned, which is the # safer way for this list to be wrong. # # `client/scripts` and `server/scripts` are in, not out: checkExternals.js and # checkImports.js *are* the enforcement of MODULE_API.md §3.6 and §5.1, they # each carry their own test suite, and both have already shipped defects that a # reviewer missed (see MODULE_SYSTEM.md §2.7.1). Build code that decides whether # a release is allowed out is not throwaway code. sonar.sources=server,client/src,client/scripts # Test code is analysed separately from sources so coverage/metrics attribute # correctly. Both halves run on Node's built-in test runner (no browser/DOM): # the server suite is CommonJS behind test/_setup.js, the client's is ESM. sonar.tests=server/test,client/test sonar.test.inclusions=server/test/**/*.test.js,client/test/**/*.test.js # Coverage. The sonarqube.yml workflow runs both suites with Node's built-in # test-coverage and writes an LCOV report for each BEFORE the scan runs; without # them the dashboard shows 0% (the scanner never executes tests itself). Both # suites are invoked from the repo root so the `SF:` paths come out # repo-root-relative (server/..., client/src/...) and the scanner resolves them # against the project base dir. sonar.javascript.lcov.reportPaths=server/coverage/lcov.info,client/coverage/lcov.info # Test execution ("Unit Tests" measure). A SEPARATE report from coverage: the # lcov files above only populate Coverage, so without this the dashboard shows a # coverage % but an empty "Unit Tests" tile. Written by scripts/sonar-test-reporter.mjs, # a copy of core's — a pure leaf build helper, which is the side of the vendoring # line that may be copied (MODULE_SYSTEM.md §2.7.1). sonar.testExecutionReportPaths=server/coverage/test-execution.xml,client/coverage/test-execution.xml # Never analyse dependencies, build output, generated artifacts, or fixtures. # # `client/dist` is the built chunk (gitignored, but the workflow builds it before # scanning because client/test/{build,registration}.test.js import it). # `server/swagger/doc.js` and the two committed generated artifacts at the repo # root are inputs to and outputs of swagger-autogen, not hand-written code. sonar.exclusions=**/node_modules/**,server/test/**,client/test/**,client/dist/**,server/swagger/**,server/data/**,server/coverage/**,client/coverage/**,**/*.min.js sonar.sourceEncoding=UTF-8