Dear all,
I have a C# project with a web.config file that does not have a project solution file. For this reason, I am analyzing this project with sonar-scanner-cli (versión 5.0.1.3006) with Server SonarQube Enterprise 9.9.6
The reason of this post is to ask why the xml scanner does not detect a hotspot regarding hard-coded passwords. I have another project that indeed has sln file and when I use the MsBuild Scanner, the hotspot is detected. See screenshots.
Hotspot detected with MSBUILD
Hotspot not detected with sonar-scanner:
Thank you.