External issues not loading into SonarCloud dashboard

  • ALM used: GitHub
  • CI system used: Circle CI
  • Scanner command used: CircleCI orb
  • Languages of the repository: Golang

I’ve tested golangci-lint and the output looks right, but there is no vulnerabilities in the dashboard, a different result compared to running locally. Do you know what is happening here? See that the line INFO: Importing /home/circleci/repo/report.xml is there sucessfully importing. Look how data about other things as coverage is unchanged, differently of other branches.

INFO: Importing /home/circleci/repo/report.xml
Hello @GabrielNegreirosLima

If I understand correctly, you created a new branch to add the support of golangci-lint. When looking locally in the report, you can see issues, but when analyzing the branch/PR, nothing is reported? Did I get it right?

In fact, the trick is that in a branch/PR, only the issues related to the new code will be displayed. Thinking about it, that’s fair: you are discovering already existing issues, they should not appear on new code.

If you want to make sure everything is working, you could try to add a piece of code with a golangci-lint issue and see if it is reported.
Once merged, the issues already existing will be reported in your project, and new ones will be reported in the new codes.

Hope it helps.



Hi @Quentin.

Thank you for your reply. Yes, you got it, and I have added a new line with a really close statement that was flagged as a vulnerability with golangci-lint and it looks like it’s been detected by Sonar, but the vulnerability has not. Look at the screenshot below:


If a issue was risen with that new line, it would appear here, right?


The line of the issue should match exactly the line of the new code, otherwise, we will not report it in the PR panel. Adding one line after will not do the trick, the code you are adding should contain an issue.

At this point, if it is still not working, it would be great if you could provide us a reproducer: a code sample with the related golangci-lint report.