docs(security): SonarQube triage inventory (133 issues) - #383
docs(security): SonarQube triage inventory (133 issues)#383marlon-costa-dc wants to merge 2 commits into
Conversation
Inventario das issues SonarCloud com severidade, tipo, regra, componente e linha. Totais: BLOCKER 5, CRITICAL 24, MAJOR 27, MINOR 77 Tipos: VULNERABILITY 4, BUG 6, CODE_SMELL 123 Bead: mro-2wjm.2 Nenhuma alteracao de codigo de producao.
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…rule messages Cada achado agora traz: - codigo real numerado extraido da worktree (linha >>> = sink) - mensagem completa da regra (descricao do problema e do fix) - CWE/classe de vulnerabilidade e effort onde disponivel
|



Triagem SonarCloud — inventário
133 issues — BLOCKER 5, CRITICAL 24, MAJOR 27, MINOR 77
Tipos: VULNERABILITY 4, BUG 6, CODE_SMELL 123
Bead:
mro-2wjm.2Conteúdo
docs/security/sonarqube-triage.md: severidade, tipo, regra, componente e linha de cada issue, com coluna de decisão (corrigir/falso-positivo/risco-aceito).Nenhuma alteração de código.
Prioridade: BLOCKER → CRITICAL → VULNERABILITY → MAJOR. CODE_SMELL em volume sugere correção de padrão na causa raiz, não issue a issue.
Dados brutos:
~/sonarqube-violations/by-repo/flext-sh_flext-core.jsonSummary by cubic
Add a SonarCloud triage inventory for
flext-sh/flext-coreindocs/security/sonarqube-triage.mdcovering 133 issues, with severity, type, rule, component, line, and a decision column. Entries now include numbered code snippets (>>> marks the sink), full rule messages, CWE/vulnerability class, and estimated effort; documentation only, no code changes.Written for commit 1444fe0. Summary will update on new commits.