Skip to content

Conversation

@alaudaa-renovate
Copy link

@alaudaa-renovate alaudaa-renovate bot commented Oct 9, 2025

This PR contains the following updates:

Package Change Age Confidence
org.sonarsource.text:sonar-text-plugin (source) 2.26.1.9976 -> 2.34.0.9939 age confidence
org.sonarsource.iac:sonar-iac-plugin (source) 1.48.1.18410 -> 1.53.0.16993 age confidence
org.sonarsource.xml:sonar-xml-plugin (source) 2.12.2.6335 -> 2.14.2.7437 age confidence
org.sonarsource.kotlin:sonar-kotlin-plugin (source) 2.22.1.6674 -> 2.23.0.6359 age confidence
org.sonarsource.python:sonar-python-plugin (source) 5.7.1.26730 -> 5.14.2.29072 age confidence
org.sonarsource.plugins.cayc:sonar-cayc-plugin (source) 2.4.0.2018 -> 2.6.0.3665 age confidence
org.sonarsource.php:sonar-php-plugin (source) 3.41.0.12692 -> 3.53.0.15220 age confidence
org.sonarsource.javascript:sonar-javascript-plugin (source) 11.2.0.34013 -> 11.7.1.36988 age confidence
org.sonarsource.java:sonar-java-symbolic-execution-plugin (source) 8.8.0.37665 -> 8.19.0.1586 age confidence
org.sonarsource.java:sonar-java-plugin (source) 8.18.0.40025 -> 8.22.0.41895 age confidence
org.sonarsource.jacoco:sonar-jacoco-plugin (source) 1.3.0.1538 -> 1.4.0.4946 age confidence
org.sonarsource.html:sonar-html-plugin (source) 3.18.0.5605 -> 3.22.0.7011 age confidence
org.sonarsource.flex:sonar-flex-plugin (source) 2.14.0.5032 -> 2.16.0.6009 age confidence
org.sonarsource.dotnet:sonar-vbnet-plugin (source) 10.4.0.108396 -> 10.16.2.130377 age confidence
org.sonarsource.dotnet:sonar-csharp-plugin (source) 10.4.0.108396 -> 10.16.2.130377 age confidence
org.sonarsource.slang:sonar-scala-plugin (source) 1.18.2.1879 -> 1.20.1.1884 age confidence
org.sonarsource.slang:sonar-ruby-plugin (source) 1.18.1.375 -> 1.21.1.1877 age confidence
org.sonarsource.api.plugin:sonar-plugin-api-test-fixtures (source) 11.0.0.2664 -> 11.4.0.2922 age confidence
org.sonarsource.api.plugin:sonar-plugin-api (source) 11.0.0.2664 -> 11.4.0.2922 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

SonarSource/sonar-xml (org.sonarsource.xml:sonar-xml-plugin)

v2.14.2.7437

Compare Source

Release notes - SonarXML - 2.14.2

Bug

SONARXML-168 Unable to parse XML file when attribute is too long

Task

SONARXML-271 Update parent POM and company name

SONARXML-272 Update sonar-analyzer-commons

SONARXML-273 Update sonar-plugin-api

SONARXML-275 Build with Java 21

SONARXML-279 Update rule metadata

SONARXML-283 Prevent script injection S7630

SONARXML-284 Update parent pom to 85.0.0.3035

SONARXML-291 Update parent pom to 86.0.0.3040

SONARXML-292 Prepare next development iteration 2.14.2

False Negative

SONARXML-183 [S5344] Add detection of passwords in Web.config files

SONARXML-264 FN on S2068 in appSettings in web.config of .NET Web Applications

SONARXML-274 S3330 Does not detect missing httpOnlyCookies in .NET's web.config

SONARXML-277 Add XML to S5734 (MIME sniffing attacks) and detect it in IIS config

v2.14.1.7429

Compare Source

Release notes - SonarXML - 2.14.1

Task

SONARXML-283 Prevent script injection S7630

SONARXML-284 Update parent pom to 85.0.0.3035

v2.14.0.7419

Compare Source

Release notes - SonarXML - 2.14

Bug

SONARXML-168 Unable to parse XML file when attribute is too long

Task

SONARXML-242 Update Slack notification in .github/workflows/slack_notify.yml

SONARXML-243 Bump orchestrator to version 5.5 or greater

SONARXML-246 Use "sonar.scanner.skipJreProvisioning" in integration tests

SONARXML-250 Ignore test fixtures for SCA scanning

SONARXML-253 Update GH release and releasability actions

SONARXML-254 Create Github action to prepare next development iteration.

SONARXML-255 Delete ws_scan_task

SONARXML-257 Migrate Cirrus build to Github action

SONARXML-258 Migrate QA task to GitHub action

SONARXML-259 Migrate ruling tasks to GitHub actions

SONARXML-261 Create PR cleanup action

SONARXML-268 Finalize CI migration

SONARXML-269 Use correct build number in the promote job

SONARXML-271 Update parent POM and company name

SONARXML-272 Update sonar-analyzer-commons

SONARXML-273 Update sonar-plugin-api

SONARXML-275 Build with Java 21

SONARXML-279 Update rule metadata

False Negative

SONARXML-183 [S5344] Add detection of passwords in Web.config files

SONARXML-264 FN on S2068 in appSettings in web.config of .NET Web Applications

SONARXML-274 S3330 Does not detect missing httpOnlyCookies in .NET's web.config

SONARXML-277 Add XML to S5734 (MIME sniffing attacks) and detect it in IIS config

Epic

SONARXML-256 Migrate Cirrus CI tasks to GitHub Actions

v2.13.1.6351

Compare Source

Release notes - SonarXML - 2.13.1

Task

SONARXML-287 Prepare next development iteration 2.13.1

SONARXML-288 Prepare 2.13.1

v2.13.0.5938

Compare Source

Release notes - SonarXML - 2.13


This release brings a new rule from the M8 category of OWASP Mobile Top 10 to SonarXML: S7207.

What's Changed

Full Changelog: SonarSource/sonar-xml@2.12.0.5749...2.13.0.5938

SonarSource/sonar-kotlin (org.sonarsource.kotlin:sonar-kotlin-plugin)

v2.23.0.6359

Compare Source


SonarSource/sonar-cayc-stats-plugin (org.sonarsource.plugins.cayc:sonar-cayc-plugin)

v2.6.0.3665

Compare Source

What's Changed

Full Changelog: SonarSource/sonar-cayc-stats-plugin@2.5.0.2588...2.6.0.3665

v2.5.0.2588

Compare Source

What's Changed

Full Changelog: SonarSource/sonar-cayc-stats-plugin@2.2.0.619...2.5.0.2588

SonarSource/sonar-php (org.sonarsource.php:sonar-php-plugin)

v3.53.0.15220

Compare Source

Release notes - SonarPHP - 3.53

Rotations of binary signing keys

v3.52.0.15197

Compare Source

Release notes - SonarPHP - 3.52

False Positive

SONARPHP-1673 S1192 should not raise on "importmap.php"
SONARPHP-1674 S101 should not raise for generated classes for Yii DB migration
SONARPHP-1675 S100 should adapt to Wordpress naming conventions
SONARPHP-1680 S1448 should not raise on classes that are entity of a database
SONARPHP-1681 S2003 and S4833 should not raise on Laravel-generated code

Improvement

SONARPHP-1738 Update S3776 Cognitive Complexity to account for PHP pipe operator
SONARPHP-1754 Improve Wordpress Framework detection
SONARPHP-1761 Drop set of deprecated hotspots
SONARPHP-1762 Migrate Pilot Group of Hotspots to Vulnerabilities

v3.51.0.15001

Compare Source

Release notes - SonarPHP - 3.51

New Feature

SONARPHP-1729 Support Pipe operator (PHP 8.5 feature)
SONARPHP-1734 Support void cast (PHP 8.5 feature)
SONARPHP-1735 Support final property promotion (PHP 8.5 feature)
SONARPHP-1736 Support Closures in constant expressions (PHP 8.5 feature)

False Positive

SONARPHP-1534 S1192 should not report an issue on Laravel-like validation strings
SONARPHP-1541 S1172 should not raise an issue on $subject parameter for before, after and around methods
SONARPHP-1581 S2830 should not flag default values of constructor parameters

v3.50.0.14927

Compare Source

Release notes - SonarPHP - 3.50

v3.49.0.13624

Compare Source

Release notes - SonarPHP - 3.49

Improvement

SONARPHP-1692 Optimize keyword parsing by replacing regex-based logic

v3.48.0.13483

Compare Source

Release notes - SonarPHP - 3.48

Rule meta data updates

v3.47.0.13433

Compare Source

Release notes - SonarPHP - 3.47

Maintenance release, rule meta data updates

v3.46.1.15272

Compare Source

Rotations of binary signing keys

v3.46.0.13151

Compare Source

Release notes - SonarPHP - 3.46

False Positive

SONARPHP-1631 S6328: Do not raise on escape sequences that are using numbers

Improvement

SONARPHP-1643 Error level log should be used only for non-recoverable error that stop the analyzer

v3.45.0.12991

Compare Source

Fixes rules descriptions to MQR.

v3.44.0.12898

Compare Source

Release notes - SonarPHP - 3.44

Improvement

SONARPHP-1626 S1541 should detect `elseif` clauses

v3.43.0.12862

Compare Source

Release notes - SonarPHP - 3.43

False Positive

SONARPHP-1577 S4144 should not report an issue on method/function using the __FUNCTION__ constant

SONARPHP-1590 S1192 should not raise for HTML tags

Bug

SONARPHP-1605 PHP parser should support array merges in static variables

v3.42.2.15271

Compare Source

Rotations of binary signing keys

v3.42.1.12942

Compare Source

Release notes - SonarPHP - 3.42.1

Improvement

SONARPHP-1633 Fix discrepancies between MQR and severity for PHP rules

v3.42.0.12795

Compare Source

Release notes - SonarPHP - 3.42

Bug

SONARPHP-1600 Parser should support match statements in unary expressions

SonarSource/sonar-javascript (org.sonarsource.javascript:sonar-javascript-plugin)

v11.7.1.36988: 11.7.1

Compare Source

Rotation of binary signing keys

What's Changed

Full Changelog: SonarSource/SonarJS@11.7.0.36965...11.7.1.36988

v11.7.0.36965: 11.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: SonarSource/SonarJS@11.6.0.36606...11.7.0.36965

v11.6.0.36606: 11.6.0

Compare Source

What's Changed

New Contributors

Full Changelog: SonarSource/SonarJS@11.5.0.35357...11.6.0.36606

v11.5.0.35357: 11.5.0

Compare Source

What's Changed

Full Changelog: SonarSource/SonarJS@11.4.0.34681...11.5.0.35357

v11.4.1.34873: 11.4.1

Compare Source

Full Changelog: SonarSource/SonarJS@11.4.0.34681...11.4.1.34873

v11.4.0.34681: 11.4.0

Compare Source

What's Changed

Full Changelog: SonarSource/SonarJS@11.3.0.34350...11.4.0.34681

v11.3.0.34350: 11.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: SonarSource/SonarJS@11.2.0.34013...11.3.0.34350

SonarSource/sonar-java-symbolic-execution (org.sonarsource.java:sonar-java-symbolic-execution-plugin)

v8.19.0.1586

Compare Source

Release notes - JavaSE - 8.19

Bug

JAVASE-145 Change project key for sonar-java-symbolic-execution on SQC EU and US to be consistent with Next

Task

JAVASE-13 Prepare next development iteration

JAVASE-153 Update parent pom 85.0.0.3035 and license headers

JAVASE-158 Update parent pom to version 86.0.0.3040

JAVASE-159 Update release and releasability workflows

v8.18.1.347

Compare Source

Release notes - JavaSE - 8.18.1

Task

JAVASE-15 Prepare next development iteration

JAVASE-16 Upgrade commons-lang3 to 3.18.0

v8.18.0.242

Compare Source

Release notes - JavaSE - 8.18

Task

JAVASE-10 Prepare next development iteration

JAVASE-12 Update rule metadata

Improvement

JAVASE-11 Remove DivisionByZeroCheck registra


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 11 times, most recently from 7010d3c to be7ab79 Compare October 20, 2025 00:54
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 3 times, most recently from 83c10b3 to 3c25e54 Compare October 24, 2025 18:11
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 6 times, most recently from e519a75 to 062fc30 Compare November 3, 2025 09:05
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 2 times, most recently from df7b499 to b114dc2 Compare November 7, 2025 22:14
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 6 times, most recently from 0e86747 to 9136cb1 Compare November 20, 2025 19:00
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch from 9136cb1 to 9bf34df Compare November 21, 2025 14:50
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 6 times, most recently from a6a7fd3 to 7b86eae Compare December 1, 2025 12:23
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch 11 times, most recently from 2b9035f to 4ed61ab Compare December 9, 2025 11:06
@alaudaa-renovate alaudaa-renovate bot force-pushed the renovate/sonarqube-plugins-minor branch from 4ed61ab to 246f6c2 Compare December 9, 2025 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant