CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Dealing with SonarQube Cloud: Initial Results from a Mining Software Repository Study
University of Salerno, Italy.
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.ORCID iD: 0000-0002-0679-4361
University of Salerno, Italy.
2025 (English)In: International Symposium on Empirical Software Engineering and Measurement, IEEE Computer Society, 2025, p. 372-378Conference paper, Published paper (Refereed)
Abstract [en]

Background: Static Code Analysis (SCA) tools are widely adopted to enforce code quality standards. However, little is known about how open-source projects use and customize these tools. Aims: This paper investigates how GitHub projects use and customize a popular SCA tool, namely SonarQube Cloud.

Method: We conducted a mining study of GitHub projects that are linked through GitHub Actions to SonarQube Cloud projects.

Results: Among 321 GitHub projects using SonarQube Cloud, 81% of them are correctly connected to SonarQube Cloud projects, while others exhibit misconfigurations or restricted access. Among 265 accessible SonarQube Cloud projects, 75% use the organization's default quality gate, i.e., a set of conditions that deployed source code must meet to pass automated checks. While 55% of the projects use the built-in quality gate provided by SonarQube Cloud, 45% of them customize their quality gate with different conditions. Overall, the most common quality conditions align with SonarQube Cloud's 'Clean as You Code' principle and enforce security, maintainability, reliability, coverage, and a few duplicates on newly added or modified source code.

Conclusions: Many projects rely on predefined configurations, yet a significant portion customize their configurations to meet specific quality goals. Building on our initial results, we envision a future research agenda linking quality gate configurations to actual software outcomes (e.g., improvement of software security). This would enable evidence-based recommendations for configuring SCA tools like SonarQube Cloud in various contexts. 

Place, publisher, year, edition, pages
IEEE Computer Society, 2025. p. 372-378
Series
International Symposium on Empirical Software Engineering and Measurement, ISSN 1949-3770, E-ISSN 1949-3789
Keywords [en]
Automation Policies, Coding Issues, Continuous Integration and Delivery, SonarCloud, SonarLint, SonarQube, Static Code Analysis tools, Automation, Codes (symbols), Computer programming languages, Data mining, Open source software, Open systems, Quality control, Automation policy, Coding issue, Condition, Continuous integrations, Quality gates, Sonar
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-29285DOI: 10.1109/ESEM64174.2025.00035Scopus ID: 2-s2.0-105032656974ISBN: 9798331591472 (print)OAI: oai:DiVA.org:bth-29285DiVA, id: diva2:2049064
Conference
2025 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, ESEM 2025, Honolulu, Oct 2-3, 2025
Projects
NEXTGenerationEU
Funder
European CommissionAvailable from: 2026-03-27 Created: 2026-03-27 Last updated: 2026-03-27Bibliographically approved

Open Access in DiVA

fulltext(208 kB)20 downloads
File information
File name FULLTEXT01.pdfFile size 208 kBChecksum SHA-512
9e5552b62f18999864b411375a10fad026c9b00cdea73c6f947534f479547c5d1f5d3c17161d490e1194abaa99506b1e4f7bff8a357ff2bd9f0d8b1f923be652
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Fucci, Davide

Search in DiVA

By author/editor
Fucci, Davide
By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 494 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf