← SonarQubeCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to SonarQube
Snapshot Sep 30, 2026 · 23:13 UTC · version 2.6.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "sonar-list-issues",
"description": "Search and filter SonarQube issues for a project, branch, or pull request via sonarqube-cli (`-p` is always required on the CLI; resolve the key from user arguments or sonar-project.properties)",
"included_files": [],
"skill_md_contents": "---\nname: sonar-list-issues\ndescription: Search and filter SonarQube issues for a project, branch, or pull request via sonarqube-cli (`-p` is always required on the CLI; resolve the key from user arguments or sonar-project.properties)\nargument-hint: \"[project-key?] [--severities values] [--statuses values] [--branch name]\"\nallowed-tools: Read, Grep, Bash(sonar:*)\n---\n\n# SonarQube — List Issues\n\nSearch for issues in a SonarQube project using the `sonarqube-cli`.\n\nUnlike SonarQube MCP tools (which may use a default project from integration), **`sonar list issues` always requires `-p <project-key>`**. Resolve the key from the user-provided arguments or `sonar-project.properties` before running the CLI.\n\n## Usage\n\n```\nsonar-list-issues # issues in the current project\nsonar-list-issues my-project # issues in a specific project key\nsonar-list-issues my-project --severities CRITICAL,BLOCKER # filter by severities\nsonar-list-issues my-project --statuses OPEN,CONFIRMED # filter by status\nsonar-list-issues my-project --branch main # on a specific branch\nsonar-list-issues my-project --pr 42 # on a pull request\n```\n\n## Prerequisites\n\nThis skill uses the `sonarqube-cli` command. The CLI must be installed and authenticated before proceeding.\n\n**Before proceeding**, verify that `sonar` is available on your PATH and authenticated. If it is not, do not attempt to call any alternative commands or invent alternatives, and show the user:\n\n> Unable to list issues.\n>\n> **Possible causes:**\n> - `sonarqube-cli` not installed or not authenticated — invoke the sonar-integrate skill\n> - Project key is wrong or missing — `-p` is mandatory for `sonar list issues`; invoke the sonar-list-projects skill or set `sonar.projectKey` in `sonar-project.properties`\n\nThen ask the user (yes/no) whether to run the sonar-integrate skill now. Briefly explain what it does: it checks the SonarQube setup on their machine — installing or updating `sonarqube-cli` and verifying authentication — and re-configures the integration for this agent, including the SonarQube MCP server and secrets-scanning hooks. If they confirm, invoke the sonar-integrate skill yourself and follow it end-to-end in this session, then re-check and continue; if they decline, stop.\n\n## Instructions\n\n### Step 1: Resolve the project key\n\nThis flow uses **`sonar list issues`** (CLI), not MCP. The CLI **always** needs **`-p <project-key>`** — do not invoke it without a resolved key.\n\n- If the user provided a project key, use it.\n- Otherwise look for `sonar.projectKey` in `sonar-project.properties` at the repo root.\n- If still not found, **do not run** `sonar list issues`. Tell the user: *\"Invoke the sonar-list-projects skill to find your project key, then re-run with that key,\"* or add `sonar.projectKey` to `sonar-project.properties`. (MCP integration defaults do **not** apply to this CLI command.)\n\n### Step 2: Parse optional flags from the user-provided arguments\n\n| Flag | Maps to CLI option |\n| ------------------------ | ------------------ |\n| `--severities <values>` | `--severities` |\n| `--statuses <values>` | `--statuses` |\n| `--branch <name>` | `--branch` |\n| `--pr <id>` | `--pull-request` |\n\n> `sonar list issues` does **not** support filtering by issue type, rule, tag, or component, nor a `--resolved` flag. Only the options above (plus `--format`, `--page`, and `--page-size`) exist. To filter by rule/type/tag/component or to drill into a single file, use the MCP-based skills (e.g. sonar-analyze for a file, or `mcp__sonarqube__search_sonar_issues_in_projects`).\n\n### Step 3: Validate arguments\n\nBefore building the command, validate each user-supplied value against the following rules. If any value fails validation, stop and tell the user what was rejected and why — do not run the command. Validate the resolved project key (from args or `sonar-project.properties`) against the project-key pattern before running the CLI.\n\n| Argument | Allowed pattern |\n| -------------- | ------------------------------------------------------------------------------------- |\n| project key | `^[a-zA-Z0-9_\\-\\.:]+$` |\n| `--severities` | comma-separated subset of: `INFO`, `MINOR`, `MAJOR`, `CRITICAL`, `BLOCKER`, `HIGH`, `MEDIUM`, `LOW` |\n| `--statuses` | comma-separated subset of: `OPEN`, `CONFIRMED`, `FALSE_POSITIVE`, `ACCEPTED`, `FIXED` |\n| `--branch` | `^[a-zA-Z0-9_\\-\\./]+$` |\n| `--pr` | digits only |\n\n### Step 4: Run `sonar list issues`\n\nBuild and run the command using a shell command. **Always** pass **`-p`** with the key resolved in Step 1.\n\n```bash\nsonar list issues -p <project-key> --format toon [--severities <values>] [--statuses <values>] [--branch <name>] [--pull-request <id>]\n```\n\nOnly include optional flags that were provided.\n\n### Step 5: Format the results\n\n**If issues are found**, present a summary line then a table sorted by severity then line number:\n\n```markdown\n## SonarQube Issues — `my-project` (branch: `main`)\n\nFound **12 issue(s)**:\n\n| File | Line | Severity | Rule | Message |\n| -------------------- | ---- | --------- | ------------ | ----------------------------- |\n| src/auth/login.py | 12 | 🔴 Blocker | python:S2077 | SQL injection risk |\n| src/utils/helpers.py | 34 | 🟠 High | python:S2259 | Null dereference |\n| src/api/routes.py | 67 | 🟡 Medium | python:S3776 | Cognitive complexity too high |\n```\n\nSeverity icons (the label depends on the server version):\n- 🔴 Blocker\n- 🟠 Critical / High\n- 🟡 Major / Medium\n- 🔵 Minor / Low\n- ⚪ Info\n\n**If no issues are found**:\n\n```markdown\n## SonarQube Issues — `my-project`\n\n✅ No issues found.\n```\n\n### Step 6: Next steps\n\n- To fix a specific issue: *\"Ask me to fix `<rule>` at `<file>:<line>`.\"*\n- To check the quality gate: *\"Invoke the sonar-quality-gate skill.\"*\n"
}SHA-256: 689139121f977cbfaad5056a93350b17fe28e9b00c92dc8b4d49aec9fcd18a03