Replies: 1 comment
-
These approaches are insecure. The whole point with forks is to run SonarCloud analysis with no access to the upstream repo (because it involves for example running CMake with Running the analysis like they do is absolutely insecure. What if malicious author of pull request just add some code to his |
Beta Was this translation helpful? Give feedback.
-
According to this approach it is possible to enable SonarQube analysis for forked pull requests. Since we don't do compilation for SQ stage this will not impact much on the performance of Github Actions.
Beta Was this translation helpful? Give feedback.
All reactions