Skip to content

refactor: update build and sonar configuration - #8

Merged
matusso merged 1 commit into
masterfrom
refactor-sonar-build-config-cpp-cast
Apr 7, 2026
Merged

matusso merged 1 commit into
masterfrom
refactor-sonar-build-config-cpp-cast

Conversation

@matusso

@matusso matusso commented Apr 7, 2026

Copy link
Copy Markdown
Owner

Update sonar-scanner setup to build from source instead of
downloading prebuilt binaries. This requires installing additional
dependencies including maven and cmake.

Reorganize workflow steps to install dependencies before sonar-scanner
setup. Update build wrapper output directory path to match project
structure.

Improve C++ code quality by replacing C-style cast with modern
static_cast in ssllabs.cpp.

Update sonar-scanner setup to build from source instead of
downloading prebuilt binaries. This requires installing additional
dependencies including maven and cmake.

Reorganize workflow steps to install dependencies before sonar-scanner
setup. Update build wrapper output directory path to match project
structure.

Improve C++ code quality by replacing C-style cast with modern
static_cast in ssllabs.cpp.
@matusso
matusso merged commit e656ff8 into master Apr 7, 2026
5 checks passed
@matusso
matusso deleted the refactor-sonar-build-config-cpp-cast branch April 7, 2026 17:26
@sonarqubecloud

sonarqubecloud Bot commented Apr 7, 2026

Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the SonarQube build wrapper output path and refactors a pointer cast in the SSL Labs source code to use a modern C++ static cast. Feedback highlights a potential buffer over-read in the CURL write callback, suggesting the use of the buffer size during string appending, and recommends transitioning to a compilation database for more robust SonarQube analysis.

Comment thread src/ssllabs.cpp
size_t realsize = size * nmemb;

std::string *mem = (std::string *) up;
auto *mem = static_cast<std::string *>(up);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-high high

While refactoring the cast, note that the subsequent mem->append(buf) is unsafe. CURL's buffer is not null-terminated and may contain null bytes. Use mem->append(buf, realsize) instead to prevent buffer over-reads and ensure all data is correctly captured.

Comment thread sonar-project.properties

# Use this if you have a specific build tool (optional)
sonar.cfamily.build-wrapper-output=build_wrapper_output_directory
sonar.cfamily.build-wrapper-output=build/wrapper_output_directory

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

For CMake projects, using a compilation database (compile_commands.json) is preferred over the build-wrapper. It's more robust and easier to maintain. You can enable it with -DCMAKE_EXPORT_COMPILE_COMMANDS=ON and then uncomment and set sonar.cfamily.compile-commands=build/compile_commands.json.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant