docs(security): SonarQube triage inventory (11 issues) - #82
docs(security): SonarQube triage inventory (11 issues)#82marlon-costa-dc wants to merge 2 commits into
Conversation
Inventario das issues SonarCloud com severidade, tipo, regra, componente e linha. Totais: BLOCKER 0, CRITICAL 3, MAJOR 6, MINOR 2 Tipos: VULNERABILITY 4, BUG 0, CODE_SMELL 7 Bead: mro-2wjm.9 Nenhuma alteracao de codigo de producao.
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…rule messages Cada achado agora traz: - codigo real numerado extraido da worktree (linha >>> = sink) - mensagem completa da regra (descricao do problema e do fix) - CWE/classe de vulnerabilidade e effort onde disponivel
|



Triagem SonarCloud — inventário
11 issues — BLOCKER 0, CRITICAL 3, MAJOR 6, MINOR 2
Tipos: VULNERABILITY 4, BUG 0, CODE_SMELL 7
Bead:
mro-2wjm.9Conteúdo
docs/security/sonarqube-triage.md: severidade, tipo, regra, componente e linha de cada issue, com coluna de decisão (corrigir/falso-positivo/risco-aceito).Nenhuma alteração de código.
Prioridade: BLOCKER → CRITICAL → VULNERABILITY → MAJOR. CODE_SMELL em volume sugere correção de padrão na causa raiz, não issue a issue.
Dados brutos:
~/sonarqube-violations/by-repo/flext-sh_flext-ldap.jsonSummary by cubic
Added
docs/security/sonarqube-triage.mdto inventory SonarCloud findings forflext-ldap: 11 issues (CRITICAL 3, MAJOR 6, MINOR 2; VULNERABILITY 4, CODE_SMELL 7), with rule, component, line, and a decision column. Now enriched with full rule messages, numbered code snippets (>>>), CWE/type, and effort/debt; docs-only change, no code modified.Written for commit b3b1a41. Summary will update on new commits.