{"id":97620,"date":"2020-10-19T20:42:40","date_gmt":"2020-10-19T18:42:40","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial"},"modified":"2020-10-19T20:42:40","modified_gmt":"2020-10-19T18:42:40","slug":"kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial","title":{"rendered":"How we implemented SonarQube and recognized its great potential.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/81a4b69ed09d156ec71603b4bf32d587.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>We want to share our experience in implementing the SonarQube platform for continuous analysis and measurement of code quality into the existing development processes of the DPO system (an addition to the depository and clearing accounting system 'Alameda') of the National Settlement Depository. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>The National Settlement Depository (part of the Moscow Exchange Group) is one of the key companies in the financial infrastructure, storing and accounting for securities of Russian and foreign issuers worth over 50 trillion rubles. The increasing volume of operations conducted by the system, along with the continuous expansion of functionality, demands the maintenance of high quality source code. One of the tools to achieve this goal is the SonarQube static analyzer. In this article, we will describe the successful experience of seamlessly integrating the SonarQube static analyzer into the existing development processes of our department. <\/p>\n<p><\/p>\n<h3 id=\"kratko-ob-otdele\">About the Department<\/h3>\n<p><\/p>\n<p>Our competencies include the following modules: client payments to the NSD, electronic document management, processing trade repository messages (registering off-exchange transactions), channels for electronic interaction between clients and the NSD, and much more. Overall, we have a substantial workload concerning the technical aspects of operational activities. We work based on requests. The requests of the operators are processed by analysts: they gather client requirements and present us with their vision of how it should be reflected in the software. Next follows the standard scheme: code development \u2013 testing \u2013 pilot operation \u2013 delivery of code to the production environment to the end client. <\/p>\n<p><\/p>\n<h3 id=\"pochemu-imenno-sonarqube\">Why SonarQube?<\/h3>\n<p><\/p>\n<p>This is our department's first experience implementing a platform for code quality control \u2013 previously, we did this manually, only conducting code reviews. However, the growing workload necessitates the automation of this process. Additionally, there are inexperienced staff members on the team who are not entirely familiar with internal development regulations and are prone to making more mistakes. To ensure code quality, it was decided to implement a static code analyzer. Since SonarQube was already used in some systems of NRD, the choice was straightforward. Previously, colleagues from other divisions used it to analyze microservice code in the 'Alameda' system (NRD's proprietary depository-clearing accounting system), in CFT (an information system for managing accounting, balance sheets, and preparing mandatory and internal reports), and in several other systems. For experiments, we decided to start with the free version of SonarQube. So, let\u2019s move on to our case.<\/p>\n<p><\/p>\n<h2 id=\"process-vnedreniya\">Implementation process<\/h2>\n<p><\/p>\n<p><strong>We have<\/strong>:<\/p>\n<p><\/p>\n<ul>\n<li>automatic system build in TeamCity;<\/li>\n<li>a process for code uploading via MergeRequest from feature branches to the master branch in GitLab (development process according to GitHub Flow);<\/li>\n<li>SonarQube, configured to analyze code for the DPO system on a schedule.<\/li>\n<\/ul>\n<p><\/p>\n<p><strong>Our goal<\/strong>: to implement automatic code analysis in CI\/CD processes of the DPO.<\/p>\n<p><\/p>\n<p><strong>We need to configure<\/strong>: the process for automatic code checking with a static analyzer for every MergeRequest to the main branch.<\/p>\n<p><\/p>\n<p>That is, the target picture is as follows: as soon as a developer pushes changes to the feature branch, an automatic check for new code errors is triggered. If there are no errors, changes can be accepted; otherwise, corrections need to be made. Even at the initial stage, we were able to identify a significant number of coding errors. The system has very flexible settings: it can be configured to work according to the specific needs of developers, tailored for each system and programming style. <\/p>\n<p><\/p>\n<h3 id=\"nastroyka-qualitygate-v-sonarqube\">Configuring QualityGate in SonarQube<\/h3>\n<p><\/p>\n<p>QualityGate analysis is something we discovered in the depths of the internet. Initially, we used a different approach that was more complex and somewhat incorrect. First, we ran the scan through SonarQube twice: scanning the feature branch and the branch where we intended to merge the feature branch, and then comparing the number of errors. This method lacked stability and did not always produce accurate results. Then we learned that instead of running SonarQube twice, we could set a limit on the number of allowed errors (QualityGate) and analyze only the branch we are merging.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/1d1def0ca40039b0c61315d3b3833a33.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>So far, we are using a rather primitive code check. It is worth noting that SonarQube is incompatible with some programming languages, including Delphi. Currently, we are only analyzing PL\/SQL code for our system.<\/p>\n<p><\/p>\n<p>It works like this:<\/p>\n<p><\/p>\n<ul>\n<li>We analyze only PL\/SQL code for our project.<\/li>\n<li>In SonarQube, the QualityGate is configured so that the number of errors does not increase with a commit. <\/li>\n<li>The number of errors on the first run was 229. If the errors increase upon commit, the merge is not allowed. <\/li>\n<li>If error corrections are made, it will be possible to reconfigure QualityGate. <\/li>\n<li>You can also add new items for analysis, such as code coverage with tests, etc.<\/li>\n<\/ul>\n<p><\/p>\n<p>The workflow is as follows:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/f904169fa87e9cfb75016c1fae4104f1.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>In the script's comments, it is clear that the number of errors in the feature branch did not increase. That means everything is OK.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/004edf78aa787a2a8f6d376f64049a92.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>The Merge button becomes available.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/7870448b9c13242f8e81f44bfd91d503.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>In the comments of the script's execution, it shows that the number of errors in the feature branch has exceeded the allowable limit. That means everything is BAD.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/b18eb07b5d46ee4cf0b71b28dfec92cc.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>The Merge button is red. Currently, there is no prohibition on pushing changes with erroneous code, but this is at the discretion of the responsible developer. In the future, commits with such errors can be prohibited in the main branch.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"How we implemented SonarQube and recognized its great potential.\" src=\"\/wp-content\/uploads\/2020\/10\/353f896326bca76c25d72396386cbb13.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<h3 id=\"samostoyatelnaya-rabota-nad-oshibkami\">Self-work on errors<\/h3>\n<p><\/p>\n<p>Next, it is necessary to check all errors identified by the system because SonarQube analyzes according to its strict standards. What it considers an error may not actually be one in our code. Therefore, it is important to verify and mark whether it is truly an error, or if it is something that does not need correcting under our circumstances. This way, we reduce the number of errors. Over time, the system will learn to understand these nuances. <\/p>\n<p><\/p>\n<h2 id=\"k-chemu-my-prishli\">What we have come to<\/h2>\n<p><\/p>\n<p>Our goal was to determine whether it makes sense to automate code review in our case. The results met our expectations. SonarQube allows us to work with the languages we need, provides a fairly competent analysis, and has the potential to learn from developers' suggestions. Overall, we are satisfied with our first experience using SonarQube and plan to evolve in this direction further. We expect that in the future we will be able to save more time and effort on code review and make it of higher quality by eliminating the human factor. Perhaps, in the process, we will discover shortcomings of the platform or, on the contrary, reaffirm that it is a cool tool with great potential. <\/p>\n<p><\/p>\n<p>In this overview article, we shared our acquaintance with the static analyzer SonarQube. If you have any questions, please write them in the comments. If you are interested in this topic, in a new publication, we will describe in more detail how to set everything up correctly and write code for such checks. <\/p>\n<p><\/p>\n<p>Author of the text: <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/users\/atanya\/\" class=\"user_link\">atanya<\/a><\/noindex><\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/nsd\/blog\/523732\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u043e\u043f\u044b\u0442\u043e\u043c \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b \u0434\u043b\u044f \u043d\u0435\u043f\u0440\u0435\u0440\u044b\u0432\u043d\u043e\u0433\u043e \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u0438\u0437\u043c\u0435\u0440\u0435\u043d\u0438\u044f \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0430 \u043a\u043e\u0434\u0430 SonarQube \u0432 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u044b \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0414\u041f\u041e (\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0434\u0435\u043f\u043e\u0437\u0438\u0442\u0430\u0440\u043d\u043e-\u043a\u043b\u0438\u0440\u0438\u043d\u0433\u043e\u0432\u043e\u0433\u043e \u0443\u0447\u0435\u0442\u0430 \u00ab\u0410\u043b\u0430\u043c\u0435\u0434\u0430\u00bb) \u041d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0440\u0430\u0441\u0447\u0435\u0442\u043d\u043e\u0433\u043e \u0434\u0435\u043f\u043e\u0437\u0438\u0442\u0430\u0440\u0438\u044f. \u041d\u0430\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u0439 \u0440\u0430\u0441\u0447\u0435\u0442\u043d\u044b\u0439 \u0434\u0435\u043f\u043e\u0437\u0438\u0442\u0430\u0440\u0438\u0439 (\u0433\u0440\u0443\u043f\u043f\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u00ab\u041c\u043e\u0441\u043a\u043e\u0432\u0441\u043a\u0430\u044f \u0431\u0438\u0440\u0436\u0430\u00bb) \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043a\u043b\u044e\u0447\u0435\u0432\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0444\u0438\u043d\u0430\u043d\u0441\u043e\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b, \u0445\u0440\u0430\u043d\u0438\u0442 \u0438 \u0443\u0447\u0438\u0442\u044b\u0432\u0430\u0435\u0442 \u0446\u0435\u043d\u043d\u044b\u0435 \u0431\u0443\u043c\u0430\u0433\u0438 \u0440\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u0438\u0445 \u0438 \u0438\u043d\u043e\u0441\u0442\u0440\u0430\u043d\u043d\u044b\u0445 \u044d\u043c\u0438\u0442\u0435\u043d\u0442\u043e\u0432 \u043d\u0430 \u0441\u0443\u043c\u043c\u0443 \u0431\u043e\u043b\u0435\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97621,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u043c\u044b \u0432\u043d\u0435\u0434\u0440\u0438\u043b\u0438 SonarQube \u0438 \u043e\u0441\u043e\u0437\u043d\u0430\u043b\u0438 \u0435\u0433\u043e \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-19T18:42:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-19T18:42:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How we implemented SonarQube and realized its great potential | ProHoster","description":"We want to share.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u043c\u044b \u0432\u043d\u0435\u0434\u0440\u0438\u043b\u0438 SonarQube \u0438 \u043e\u0441\u043e\u0437\u043d\u0430\u043b\u0438 \u0435\u0433\u043e \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b | ProHoster","og:description":"\u041c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-vnedrili-sonarqube-i-osoznali-ego-bolshoj-potenczial","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-19T18:42:40+00:00","article:modified_time":"2020-10-19T18:42:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97620","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:16:26","updated":"2022-09-28 13:56:02","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=97620"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/97620\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/97621"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=97620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=97620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=97620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}