Issues in new code not detected on branch

Hi,

We are experiencing problems when issues on new code are only detected after they are merged to master. Here is an example of such issues:

  1. Oct7th - Two new parameters were added to a method in a developer branch and it crossed the threshold of maximum of 7 parameter:

  2. Oct 7th - SonarQube ran analysis on the developer branch, detected the issue, but did not recognize that it was new code:

  3. Oct 8th - The developer branch was merged to master, SonarQube detected it as new code and failed the build:

Here is some extra information:

  1. SonarQube Server - Developer Edition v2025.4.2 (112048)

  2. Project configuration for new code:

    1. for master branch - compare to previous version
    2. for developer branches - compare to master

Hi @SergiiG,

To clarify: the issue was detected, but it seems the relevant code was not recognized as new in your branch.

Could you please provide a screenshot of your project’s New Code configuration to confirm that your branch is using the Reference Branch New Code Period, as shown below:

If this is configured correctly, I recommend creating a fresh branch, making a change to a file, and running an analysis. Check if the code is detected as new in Measures > Size > New Lines. Also, inspect the scanner logs below for warnings or issues:

15:34:14.753 INFO  Load New Code definition
15:34:14.754 DEBUG --> GET http://localhost:9000/api/new_code_periods/show.protobuf?project=ansibleexample&branch=test
15:34:14.761 DEBUG <-- 200 http://localhost:9000/api/new_code_periods/show.protobuf?project=ansibleexample&branch=test (6ms, 39-byte body)
15:34:14.762 INFO  Load New Code definition (done) | time=9ms
15:34:14.763 INFO  SCM writing changed lines
15:34:14.766 INFO  Merge base sha1: 0cb903c45fd0d10a341be5a897227244240bd1de
15:34:14.777 DEBUG SCM reported changed lines for 1 file in the branch
15:34:14.777 INFO  SCM writing changed lines (done) | time=15ms

Let me know what you find, or if the new code is detected as expected!

You are correct, issues was detected, but not recognized as new code.

Here is the screenshot of the new code config:

I am going to try the steps you provided and come back with what was discovered

OK, finally got to try it. Following your instructions, I created a new branch, ran analysis on it, made a change, ran analysis again. Here is my observations:

  1. New code detected:

  2. Issues detected in overall:

  3. But the issue is not detected as new:

  4. Logs from sonar:

    15:01:58  [INFO] Starting SonarScanner Engine...
    15:01:58  [INFO] Java 17.0.13 Eclipse Adoptium (64-bit)
    15:02:00  [INFO] Load global settings
    15:02:00  [INFO] Load global settings (done) | time=114ms
    15:02:00  [INFO] Server id: 4D5C0650-AYq-ay5fIHn0VB1XJwKd
    15:02:00  [INFO] Loading required plugins
    15:02:00  [INFO] Load plugins index
    15:02:00  [INFO] Load plugins index (done) | time=35ms
    15:02:00  [INFO] Load/download plugins
    15:02:00  [INFO] Load/download plugins (done) | time=235ms
    15:02:00  [INFO] Loaded core extensions: developer-scanner
    15:02:01  [INFO] Process project properties
    15:02:01  [INFO] Process project properties (done) | time=38ms
    15:02:01  [INFO] Project key: disaggregation
    15:02:01  [INFO] Base dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test
    15:02:01  [INFO] Working dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar
    15:02:01  [INFO] Load project settings for component key: 'disaggregation'
    15:02:01  [INFO] Load project settings for component key: 'disaggregation' (done) | time=51ms
    15:02:01  [INFO] Load project branches
    15:02:01  [INFO] Load project branches (done) | time=43ms
    15:02:01  [INFO] Load branch configuration
    15:02:01  [INFO] Detected branch/PR in 'Jenkins'
    15:02:01  [INFO] Auto-configuring branch 'sonar-test'
    15:02:01  [INFO] Load branch configuration (done) | time=4ms
    15:02:01  [INFO] Load quality profiles
    15:02:01  [INFO] Load quality profiles (done) | time=91ms
    15:02:01  [INFO] Auto-configuring with CI 'Jenkins'
    15:02:01  [INFO] Load active rules
    15:02:02  [INFO] Load active rules (done) | time=804ms
    15:02:02  [INFO] Load analysis cache
    15:02:02  [INFO] Load analysis cache | time=55ms
    15:02:02  [INFO] Branch name: sonar-test
    15:02:02  [WARNING] The property 'sonar.login' is deprecated and will be removed in the future. Please use the 'sonar.token' property instead when passing a token.
    15:02:02  [INFO] Preprocessing files...
    15:02:02  [INFO] 2 languages detected in 42 preprocessed files (done) | time=307ms
    15:02:02  [INFO] 0 files ignored because of scm ignore settings
    15:02:02  [INFO] Loading plugins for detected languages
    15:02:02  [INFO] Load/download plugins
    15:02:03  [INFO] Load/download plugins (done) | time=139ms
    15:02:03  [INFO] Load project repositories
    15:02:03  [INFO] Load project repositories (done) | time=123ms
    15:02:03  [INFO] Indexing files...
    15:02:03  [INFO] Project configuration:
    15:02:03  [INFO] 42 files indexed (done) | time=17ms
    15:02:03  [INFO] Quality profile for java: Sonar way
    15:02:03  [INFO] Quality profile for xml: Sonar way
    15:02:03  [INFO] ------------- Run sensors on module disaggregation
    15:02:03  [INFO] Load metrics repository
    15:02:03  [INFO] Load metrics repository (done) | time=32ms
    15:02:05  [INFO] Sensor JavaSensor [java]
    15:02:05  [INFO] Configured Java source version (sonar.java.source): 21, preview features enabled (sonar.java.enablePreview): false
    15:02:05  [INFO] Server-side caching is enabled. The Java analyzer will not try to leverage data from a previous analysis.
    15:02:05  [INFO] Using ECJ batch to parse 31 Main java source files with batch size 102 KB.
    15:02:06  [INFO] Starting batch processing.
    15:02:07  [INFO] The Java analyzer cannot skip unchanged files in this context. A full analysis is performed for all files.
    15:02:17  [INFO] 90% analyzed
    15:02:17  [INFO] 100% analyzed
    15:02:17  [INFO] Batch processing: Done.
    15:02:17  [INFO] Did not optimize analysis for any files, performed a full analysis for all 31 files.
    15:02:17  [INFO] Using ECJ batch to parse 10 Test java source files with batch size 102 KB.
    15:02:17  [INFO] Starting batch processing.
    15:02:19  [INFO] 100% analyzed
    15:02:19  [INFO] Batch processing: Done.
    15:02:19  [INFO] Did not optimize analysis for any files, performed a full analysis for all 10 files.
    15:02:19  [INFO] No "Generated" source files to scan.
    15:02:19  [INFO] Sensor JavaSensor [java] (done) | time=13115ms
    15:02:19  [INFO] Sensor JaCoCo XML Report Importer [jacoco]
    15:02:19  [INFO] 'sonar.coverage.jacoco.xmlReportPaths' is not defined. Using default locations: target/site/jacoco/jacoco.xml,target/site/jacoco-it/jacoco.xml,build/reports/jacoco/test/jacocoTestReport.xml
    15:02:19  [INFO] Importing 1 report(s). Turn your logs in debug mode in order to see the exhaustive list.
    15:02:19  [INFO] Sensor JaCoCo XML Report Importer [jacoco] (done) | time=131ms
    15:02:19  [INFO] Sensor IaC Docker Sensor [iac]
    15:02:19  [INFO] 0 source files to be analyzed
    15:02:19  [INFO] 0/0 source files have been analyzed
    15:02:19  [INFO] Sensor IaC Docker Sensor [iac] (done) | time=169ms
    15:02:19  [INFO] Sensor Java Config Sensor [iac]
    15:02:19  [INFO] 0 source files to be analyzed
    15:02:19  [INFO] 0/0 source files have been analyzed
    15:02:19  [INFO] Sensor Java Config Sensor [iac] (done) | time=20ms
    15:02:19  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend]
    15:02:19  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend] (done) | time=1ms
    15:02:19  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend]
    15:02:19  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend] (done) | time=0ms
    15:02:19  [INFO] Sensor SurefireSensor [java]
    15:02:19  [INFO] parsing [/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/surefire-reports]
    15:02:19  [INFO] Sensor SurefireSensor [java] (done) | time=111ms
    15:02:19  [INFO] Sensor Removed properties sensor [java]
    15:02:19  [WARNING] Property 'sonar.jacoco.reportPath' is no longer supported. Use JaCoCo's xml report and sonar-jacoco plugin.
    15:02:19  [INFO] Sensor Removed properties sensor [java] (done) | time=1ms
    15:02:19  [INFO] Sensor XML Sensor [xml]
    15:02:19  [INFO] 1 source file to be analyzed
    15:02:19  [INFO] 1/1 source file has been analyzed
    15:02:19  [INFO] Sensor XML Sensor [xml] (done) | time=323ms
    15:02:19  [INFO] Sensor Serverless configuration file sensor [security]
    15:02:19  [INFO] 0 Serverless function entries were found in the project
    15:02:19  [INFO] 0 Serverless function handlers were kept as entrypoints
    15:02:19  [INFO] Sensor Serverless configuration file sensor [security] (done) | time=11ms
    15:02:19  [INFO] Sensor AWS SAM template file sensor [security]
    15:02:19  [INFO] Sensor AWS SAM template file sensor [security] (done) | time=1ms
    15:02:19  [INFO] Sensor AWS SAM Inline template file sensor [security]
    15:02:19  [INFO] Sensor AWS SAM Inline template file sensor [security] (done) | time=1ms
    15:02:19  [INFO] Sensor javabugs [dbd]
    15:02:19  [INFO] Analyzing 144/479 functions to detect bugs.
    15:02:21  [INFO] Sensor javabugs [dbd] (done) | time=1687ms
    15:02:21  [INFO] Sensor pythonbugs [dbd]
    15:02:21  [INFO] No IR files have been included for analysis.
    15:02:21  [INFO] Sensor pythonbugs [dbd] (done) | time=1ms
    15:02:21  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper]
    15:02:21  [INFO] Available processors: 2
    15:02:21  [INFO] Using 2 threads for analysis.
    15:02:22  [INFO] Start fetching files for the text and secrets analysis
    15:02:22  [INFO] Using Git CLI to retrieve untracked files
    15:02:22  [INFO] Retrieving language associated files and files included via "sonar.text.inclusions" that are tracked by git
    15:02:22  [INFO] Starting the text and secrets analysis
    15:02:22  [INFO] 42 source files to be analyzed for the text and secrets analysis
    15:02:23  [INFO] 42/42 source files have been analyzed for the text and secrets analysis
    15:02:23  [INFO] Start fetching files for the binary file analysis
    15:02:23  [INFO] There are no files to be analyzed for the binary file analysis
    15:02:23  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper] (done) | time=2150ms
    15:02:23  [INFO] Sensor JavaSecuritySensor [security]
    15:02:23  [INFO] 29 taint analysis rules enabled.
    15:02:23  [INFO] Analyzing 128 UCFGs to detect vulnerabilities.
    15:02:27  [INFO] No entry points found.
    15:02:27  [INFO] java security sensor: Begin: 2025-11-14T20:02:23.174572599Z, End: 2025-11-14T20:02:27.098418978Z, Duration: 00:00:03.923
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:23.179877604Z, End: 2025-11-14T20:02:23.593566082Z, Duration: 00:00:00.413
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:23.179902295Z, End: 2025-11-14T20:02:23.289271793Z, Duration: 00:00:00.109
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:23.289525632Z, End: 2025-11-14T20:02:23.593460388Z, Duration: 00:00:00.303
    15:02:27    Check cache: Begin: 2025-11-14T20:02:23.593741862Z, End: 2025-11-14T20:02:23.594135183Z, Duration: 00:00:00.000
    15:02:27      Load cache: Begin: 2025-11-14T20:02:23.593755432Z, End: 2025-11-14T20:02:23.593788936Z, Duration: 00:00:00.000
    15:02:27    Create runtime call graph: Begin: 2025-11-14T20:02:23.594202726Z, End: 2025-11-14T20:02:23.669774750Z, Duration: 00:00:00.075
    15:02:27      Variable Type Analysis #1: Begin: 2025-11-14T20:02:23.595091721Z, End: 2025-11-14T20:02:23.639184979Z, Duration: 00:00:00.044
    15:02:27        Create runtime type propagation graph: Begin: 2025-11-14T20:02:23.596159355Z, End: 2025-11-14T20:02:23.628665751Z, Duration: 00:00:00.032
    15:02:27        Run SCC (Tarjan) on 820 nodes: Begin: 2025-11-14T20:02:23.629045110Z, End: 2025-11-14T20:02:23.632677575Z, Duration: 00:00:00.003
    15:02:27        Propagate runtime types to strongly connected components: Begin: 2025-11-14T20:02:23.632811292Z, End: 2025-11-14T20:02:23.639093325Z, Duration: 00:00:00.006
    15:02:27      Variable Type Analysis #2: Begin: 2025-11-14T20:02:23.645133571Z, End: 2025-11-14T20:02:23.668292766Z, Duration: 00:00:00.023
    15:02:27        Create runtime type propagation graph: Begin: 2025-11-14T20:02:23.645160344Z, End: 2025-11-14T20:02:23.662701606Z, Duration: 00:00:00.017
    15:02:27        Run SCC (Tarjan) on 820 nodes: Begin: 2025-11-14T20:02:23.662809549Z, End: 2025-11-14T20:02:23.664903789Z, Duration: 00:00:00.002
    15:02:27        Propagate runtime types to strongly connected components: Begin: 2025-11-14T20:02:23.665005324Z, End: 2025-11-14T20:02:23.668222330Z, Duration: 00:00:00.003
    15:02:27    Load config: Begin: 2025-11-14T20:02:23.669849254Z, End: 2025-11-14T20:02:27.059601697Z, Duration: 00:00:03.389
    15:02:27    Compute entry points: Begin: 2025-11-14T20:02:27.059696945Z, End: 2025-11-14T20:02:27.096381643Z, Duration: 00:00:00.036
    15:02:27  [INFO] java security sensor peak memory: 801 MB
    15:02:27  [INFO] Sensor JavaSecuritySensor [security] (done) | time=3929ms
    15:02:27  [INFO] Sensor CSharpSecuritySensor [security]
    15:02:27  [INFO] 26 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] csharp security sensor: Begin: 2025-11-14T20:02:27.101198299Z, End: 2025-11-14T20:02:27.102231803Z, Duration: 00:00:00.001
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.101613659Z, End: 2025-11-14T20:02:27.101880912Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.101617275Z, End: 2025-11-14T20:02:27.101748692Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.101805813Z, End: 2025-11-14T20:02:27.101856472Z, Duration: 00:00:00.000
    15:02:27  [INFO] csharp security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor CSharpSecuritySensor [security] (done) | time=2ms
    15:02:27  [INFO] Sensor VbNetSecuritySensor [security]
    15:02:27  [INFO] 25 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] vbnet security sensor: Begin: 2025-11-14T20:02:27.103221557Z, End: 2025-11-14T20:02:27.104034203Z, Duration: 00:00:00.000
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.103540160Z, End: 2025-11-14T20:02:27.103732394Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.103543416Z, End: 2025-11-14T20:02:27.103624856Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.103670637Z, End: 2025-11-14T20:02:27.103705846Z, Duration: 00:00:00.000
    15:02:27  [INFO] vbnet security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor VbNetSecuritySensor [security] (done) | time=2ms
    15:02:27  [INFO] Sensor PhpSecuritySensor [security]
    15:02:27  [INFO] 18 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] php security sensor: Begin: 2025-11-14T20:02:27.104912447Z, End: 2025-11-14T20:02:27.105571706Z, Duration: 00:00:00.000
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.105152853Z, End: 2025-11-14T20:02:27.105292576Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.105155652Z, End: 2025-11-14T20:02:27.105214815Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.105254434Z, End: 2025-11-14T20:02:27.105269391Z, Duration: 00:00:00.000
    15:02:27  [INFO] php security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor PhpSecuritySensor [security] (done) | time=2ms
    15:02:27  [INFO] Sensor PythonSecuritySensor [security]
    15:02:27  [INFO] 21 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] python security sensor: Begin: 2025-11-14T20:02:27.106464109Z, End: 2025-11-14T20:02:27.107176515Z, Duration: 00:00:00.000
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.106747723Z, End: 2025-11-14T20:02:27.106880717Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.106750256Z, End: 2025-11-14T20:02:27.106807998Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.106846791Z, End: 2025-11-14T20:02:27.106859149Z, Duration: 00:00:00.000
    15:02:27  [INFO] python security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor PythonSecuritySensor [security] (done) | time=1ms
    15:02:27  [INFO] Sensor JsSecuritySensor [security]
    15:02:27  [INFO] 15 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] js security sensor: Begin: 2025-11-14T20:02:27.108304594Z, End: 2025-11-14T20:02:27.109494874Z, Duration: 00:00:00.001
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.109070077Z, End: 2025-11-14T20:02:27.109211605Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.109072652Z, End: 2025-11-14T20:02:27.109127668Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.109167985Z, End: 2025-11-14T20:02:27.109179884Z, Duration: 00:00:00.000
    15:02:27  [INFO] js security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor JsSecuritySensor [security] (done) | time=3ms
    15:02:27  [INFO] Sensor KotlinSecuritySensor [security]
    15:02:27  [INFO] 28 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] kotlin security sensor: Begin: 2025-11-14T20:02:27.110372576Z, End: 2025-11-14T20:02:27.113466519Z, Duration: 00:00:00.003
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.112981679Z, End: 2025-11-14T20:02:27.113179928Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.112985785Z, End: 2025-11-14T20:02:27.113070372Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.113132452Z, End: 2025-11-14T20:02:27.113149429Z, Duration: 00:00:00.000
    15:02:27  [INFO] kotlin security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor KotlinSecuritySensor [security] (done) | time=11ms
    15:02:27  [INFO] Sensor GoSecuritySensor [security]
    15:02:27  [INFO] 9 taint analysis rules enabled.
    15:02:27  [INFO] No UCFGs have been included for analysis.
    15:02:27  [INFO] go security sensor: Begin: 2025-11-14T20:02:27.125809181Z, End: 2025-11-14T20:02:27.126652478Z, Duration: 00:00:00.000
    15:02:27    Load type hierarchy and UCFGs: Begin: 2025-11-14T20:02:27.126088878Z, End: 2025-11-14T20:02:27.126323950Z, Duration: 00:00:00.000
    15:02:27      Load type hierarchy: Begin: 2025-11-14T20:02:27.126093894Z, End: 2025-11-14T20:02:27.126189787Z, Duration: 00:00:00.000
    15:02:27      Load UCFGs: Begin: 2025-11-14T20:02:27.126273059Z, End: 2025-11-14T20:02:27.126292725Z, Duration: 00:00:00.000
    15:02:27  [INFO] go security sensor peak memory: 588 MB
    15:02:27  [INFO] Sensor GoSecuritySensor [security] (done) | time=6ms
    15:02:27  [INFO] ------------- Run sensors on project
    15:02:27  [INFO] Sensor JavaProjectSensor [java]
    15:02:27  [INFO] Sensor JavaProjectSensor [java] (done) | time=6ms
    15:02:27  [INFO] Sensor JavaArchitectureSensor [architecture]
    15:02:27  [INFO] * Protobuf reading starting | memory total=837 | free=232 | used=604 (MB)
    15:02:27  [INFO] * Reading SonarArchitecture IR data from directory "/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar/architecture/java"
    15:02:27  [INFO] * Files successfully loaded: "41" out of "41"
    15:02:27  [INFO] * Protobuf reading complete | memory total=837 | free=212 | used=624 (MB)
    15:02:27  [INFO] * Build architecture.graph.java.namespace_graph.default_perspective hierarchy graph complete (filtered=true) | memory total=837 | free=210 | used=626 (MB)
    15:02:27  [INFO] * Slicing complete | memory total=837 | free=210 | used=626 (MB)
    15:02:27  [INFO] * Cycle detection complete | memory total=837 | free=209 | used=627 (MB)
    15:02:27  [INFO] Sensor JavaArchitectureSensor [architecture] (done) | time=459ms
    15:02:27  [INFO] Sensor Zero Coverage Sensor
    15:02:27  [INFO] Sensor Zero Coverage Sensor (done) | time=1ms
    15:02:27  [INFO] Sensor Java CPD Block Indexer
    15:02:28  [INFO] Sensor Java CPD Block Indexer (done) | time=105ms
    15:02:28  [INFO] ------------- Gather SCA dependencies on project
    15:02:28  [INFO] Dependency analysis skipped
    15:02:28  [INFO] SCM Publisher SCM provider for this project is: git
    15:02:28  [INFO] SCM Publisher 2 source files to be analyzed
    15:02:28  [INFO] SCM Publisher 1/2 source file have been analyzed (done) | time=164ms
    15:02:28  [WARNING] Missing blame information for the following files:
    15:02:28  [WARNING]   * pom.xml
    15:02:28  [WARNING] This may lead to missing/broken features in SonarQube
    15:02:28  [INFO] CPD Executor 20 files had no CPD blocks
    15:02:28  [INFO] CPD Executor Calculating CPD for 11 files
    15:02:28  [INFO] CPD Executor CPD calculation finished (done) | time=15ms
    15:02:28  [INFO] SCM revision ID '3d216cf50c8acbc432498478234ee922cf773c68'
    15:02:28  [INFO] Load New Code definition
    15:02:28  [INFO] Load New Code definition (done) | time=15ms
    15:02:28  [INFO] SCM writing changed lines
    15:02:28  [INFO] Merge base sha1: 61503bfc79587cb35934a3323b3ecb7c5823fbe8
    15:02:28  [INFO] SCM writing changed lines (done) | time=316ms
    15:02:28  [INFO] Analysis report generated in 605ms, dir size=951.4 kB
    15:02:28  [INFO] Analysis report compressed in 136ms, zip size=489.4 kB
    15:02:29  [INFO] Analysis report uploaded in 70ms
    15:02:29  [INFO] ------------- Check Quality Gate status
    15:02:29  [INFO] Waiting for the analysis report to be processed (max 300s)
    15:02:34  [INFO] QUALITY GATE STATUS: PASSED - View details on https://sonarqube.devops.ketteq.com/dashboard?id=disaggregation&branch=sonar-test
    15:02:34  [INFO] Analysis total time: 33.344 s
    15:02:34  [INFO] SonarScanner Engine completed successfully
    

Hi,

To be clear, you’re not performing pull request analysis here, but branch analysis?

In that context, this logging seems odd:

I would have expected the SCM sensor to handle far more than 2 files.

These prerequisites are listed as being for PR analysis, but they apply here too. Can you make sure they’re in place, try again, and post that log?

 
Thx,
Ann

You are correct. We are performing the branch analysis. Is that wrong approach? Just to clarify that some sonar issues are detected as new, but not all (like in the example provided).

In this particular branch I changed only one file, maybe that’s why so few files were handled?

I reviewed this page: Setting up the branch analysis | SonarQube Server | Sonar Documentation, and I think we do all except setting sonar.branch.name. Do you think it matters? The branch name is recognized in sonar, and I can see it in UI, so I am not sure that’s the problem.

Ran another build with branch name specified, still not failing.

Hi,

Presumably your SCM metadata, including branch name, is picked up automatically from your environment. So whether you specify it manually or not shouldn’t matter.

This is a question of detecting “new” code. If you were running PR analysis, then everything changed versus the base branch would automatically be detected as new. In a branch analysis what’s “new” depends on what you’ve configured. However in both scenarios, you need to make sure the prerequisites are in place, so analysis has the data it needs to properly identify new code.

Since your reference branch configuration should pick up the differences versus your main branch, similar to PR analysis, let’s go back to making sure the prerequisites are in place, and to this:

How many files in your project? Only 2, total?

 
Ann

There is many more than 2 files in the project

Here are the starts from Sonar UI (for the branch):

My only guess is that only two files changed

Hi,

If we were in a PR analysis context, then only the changed files would be analyzed. This is why I asked earlier whether this was supposed to be a branch analysis or a PR analysis.

Can you make sure the prerequisites (linked above) are in place, please?

 
Thx,
Ann

  • The pull request source branch is checked out in the CI/CD host’s local repository. - yes

  • The branch being targeted by the pull request (target branch) is fetched in the CI/CD host’s local repository (This is usually done through the cloning of the remote repository by the CI pipeline). - yes, we wipe out and clone with every build

  • The CI/CD host’s local repository contains valid repository metadata (e.g. the .git folders have not been removed). Avoid any attempt at previewing the merge or actions involving your main branch. - yes, git folder is not removed

  • The code in the CI/CD host’s local repository matches the code in the remote repository (e.g once a pull request is issued, no code is added to the local branch on the CI side before analysis). - yes

  • If you use AWS CodeBuild, the LOCAL_SOURCE_CACHE feature must be disabled for accurate pull request analysis (otherwise, new code won’t be properly detected). - n/a

Hi,

Can you add -Dsonar.verbose=true and provide that full analysis log, please?

The analysis / scanner log is what’s output from the analysis command. Hopefully, the log you provide - redacted as necessary - will include that command as well.

This guide will help you find them.

 
Thx,
Ann

here:

13:50:21  + mvn sonar:sonar -P sonar-ketteq -Dsonar.verbose=true -Dnexus.url=http://nexus.internal:8081 -Dsonar.host.url=http://sonarqube.internal:9000
13:50:21  Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3" 
13:50:23  [INFO] [jenkins-event-spy] Generate /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3/maven-spy-20251202-185023-67213177016931601203222.log.tmp ...
13:50:24  [INFO] Scanning for projects...
13:50:25  [INFO] 
13:50:25  [INFO] -------------------< com.ketteq.data:disaggregation >-------------------
13:50:25  [INFO] Building disaggregation ee104d016c42eedd48f410d4aa59fb61-SNAPSHOT
13:50:25  [INFO]   from pom.xml
13:50:25  [INFO] --------------------------------[ jar ]---------------------------------
13:50:26  [INFO] 
13:50:26  [INFO] --- sonar:5.1.0.4751:sonar (default-cli) @ disaggregation ---
13:50:26  [INFO] Java 21.0.4 Amazon.com Inc. (64-bit)
13:50:26  [INFO] Linux 6.1.109-118.189.amzn2023.x86_64 (amd64)
13:50:26  [INFO] User cache: /home/ec2-user/.sonar/cache
13:50:28  [INFO] Communicating with SonarQube Server 2025.4.2.112048
13:50:28  [WARNING] Use of 'sonar.login' property has been deprecated in favor of 'sonar.token' (or the env variable alternative 'SONAR_TOKEN'). Please use the latter when passing a token.
13:50:28  [INFO] JRE provisioning: os[linux], arch[x86_64]
13:50:29  [ERROR] [stderr] Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3" 
13:50:29  [ERROR] [stderr] Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3" 
13:50:29  [INFO] Starting SonarScanner Engine...
13:50:29  [INFO] Java 17.0.13 Eclipse Adoptium (64-bit)
13:50:32  [INFO] Load global settings
13:50:32  [INFO] Load global settings (done) | time=104ms
13:50:32  [INFO] Server id: 4D5C0650-AYq-ay5fIHn0VB1XJwKd
13:50:32  [INFO] Loading required plugins
13:50:32  [INFO] Load plugins index
13:50:32  [INFO] Load plugins index (done) | time=42ms
13:50:32  [INFO] Load/download plugins
13:50:32  [INFO] Load/download plugins (done) | time=151ms
13:50:32  [INFO] Loaded core extensions: developer-scanner
13:50:32  [INFO] Process project properties
13:50:32  [INFO] Process project properties (done) | time=31ms
13:50:32  [INFO] Project key: disaggregation
13:50:32  [INFO] Base dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test
13:50:32  [INFO] Working dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar
13:50:32  [INFO] Load project settings for component key: 'disaggregation'
13:50:32  [INFO] Load project settings for component key: 'disaggregation' (done) | time=26ms
13:50:32  [INFO] Load project branches
13:50:33  [INFO] Load project branches (done) | time=36ms
13:50:33  [INFO] Load branch configuration
13:50:33  [INFO] Found manual configuration of branch/PR analysis. Skipping automatic configuration.
13:50:33  [INFO] Load branch configuration (done) | time=20ms
13:50:33  [INFO] Load quality profiles
13:50:33  [INFO] Load quality profiles (done) | time=92ms
13:50:33  [INFO] Auto-configuring with CI 'Jenkins'
13:50:33  [INFO] Load active rules
13:50:33  [INFO] Load active rules (done) | time=712ms
13:50:33  [INFO] Load analysis cache
13:50:33  [INFO] Load analysis cache | time=51ms
13:50:33  [INFO] Branch name: sonar-test
13:50:33  [WARNING] The property 'sonar.login' is deprecated and will be removed in the future. Please use the 'sonar.token' property instead when passing a token.
13:50:34  [INFO] Preprocessing files...
13:50:34  [INFO] 2 languages detected in 42 preprocessed files (done) | time=394ms
13:50:34  [INFO] 0 files ignored because of scm ignore settings
13:50:34  [INFO] Loading plugins for detected languages
13:50:34  [INFO] Load/download plugins
13:50:34  [INFO] Load/download plugins (done) | time=162ms
13:50:35  [INFO] Load project repositories
13:50:35  [INFO] Load project repositories (done) | time=173ms
13:50:35  [INFO] Indexing files...
13:50:35  [INFO] Project configuration:
13:50:35  [INFO] 42 files indexed (done) | time=68ms
13:50:35  [INFO] Quality profile for java: Sonar way
13:50:35  [INFO] Quality profile for xml: Sonar way
13:50:35  [INFO] ------------- Run sensors on module disaggregation
13:50:35  [INFO] Load metrics repository
13:50:35  [INFO] Load metrics repository (done) | time=24ms
13:50:37  [INFO] Sensor JavaSensor [java]
13:50:37  [INFO] Configured Java source version (sonar.java.source): 21, preview features enabled (sonar.java.enablePreview): false
13:50:37  [INFO] Server-side caching is enabled. The Java analyzer will not try to leverage data from a previous analysis.
13:50:37  [INFO] Using ECJ batch to parse 31 Main java source files with batch size 102 KB.
13:50:38  [INFO] Starting batch processing.
13:50:39  [INFO] The Java analyzer cannot skip unchanged files in this context. A full analysis is performed for all files.
13:50:48  [INFO] 90% analyzed
13:50:49  [INFO] 100% analyzed
13:50:49  [INFO] Batch processing: Done.
13:50:49  [INFO] Did not optimize analysis for any files, performed a full analysis for all 31 files.
13:50:49  [INFO] Using ECJ batch to parse 10 Test java source files with batch size 102 KB.
13:50:49  [INFO] Starting batch processing.
13:50:51  [INFO] 100% analyzed
13:50:51  [INFO] Batch processing: Done.
13:50:51  [INFO] Did not optimize analysis for any files, performed a full analysis for all 10 files.
13:50:51  [INFO] No "Generated" source files to scan.
13:50:51  [INFO] Sensor JavaSensor [java] (done) | time=14013ms
13:50:51  [INFO] Sensor JaCoCo XML Report Importer [jacoco]
13:50:51  [INFO] 'sonar.coverage.jacoco.xmlReportPaths' is not defined. Using default locations: target/site/jacoco/jacoco.xml,target/site/jacoco-it/jacoco.xml,build/reports/jacoco/test/jacocoTestReport.xml
13:50:51  [INFO] Importing 1 report(s). Turn your logs in debug mode in order to see the exhaustive list.
13:50:51  [INFO] Sensor JaCoCo XML Report Importer [jacoco] (done) | time=145ms
13:50:51  [INFO] Sensor IaC Docker Sensor [iac]
13:50:51  [INFO] 0 source files to be analyzed
13:50:51  [INFO] 0/0 source files have been analyzed
13:50:51  [INFO] Sensor IaC Docker Sensor [iac] (done) | time=163ms
13:50:51  [INFO] Sensor Java Config Sensor [iac]
13:50:51  [INFO] 0 source files to be analyzed
13:50:51  [INFO] 0/0 source files have been analyzed
13:50:51  [INFO] Sensor Java Config Sensor [iac] (done) | time=21ms
13:50:51  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend]
13:50:51  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend] (done) | time=1ms
13:50:51  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend]
13:50:51  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend] (done) | time=0ms
13:50:51  [INFO] Sensor SurefireSensor [java]
13:50:51  [INFO] parsing [/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/surefire-reports]
13:50:51  [INFO] Sensor SurefireSensor [java] (done) | time=148ms
13:50:51  [INFO] Sensor Removed properties sensor [java]
13:50:51  [WARNING] Property 'sonar.jacoco.reportPath' is no longer supported. Use JaCoCo's xml report and sonar-jacoco plugin.
13:50:51  [INFO] Sensor Removed properties sensor [java] (done) | time=2ms
13:50:51  [INFO] Sensor XML Sensor [xml]
13:50:51  [INFO] 1 source file to be analyzed
13:50:52  [INFO] 1/1 source file has been analyzed
13:50:52  [INFO] Sensor XML Sensor [xml] (done) | time=282ms
13:50:52  [INFO] Sensor Serverless configuration file sensor [security]
13:50:52  [INFO] 0 Serverless function entries were found in the project
13:50:52  [INFO] 0 Serverless function handlers were kept as entrypoints
13:50:52  [INFO] Sensor Serverless configuration file sensor [security] (done) | time=3ms
13:50:52  [INFO] Sensor AWS SAM template file sensor [security]
13:50:52  [INFO] Sensor AWS SAM template file sensor [security] (done) | time=1ms
13:50:52  [INFO] Sensor AWS SAM Inline template file sensor [security]
13:50:52  [INFO] Sensor AWS SAM Inline template file sensor [security] (done) | time=10ms
13:50:52  [INFO] Sensor javabugs [dbd]
13:50:52  [INFO] Analyzing 144/479 functions to detect bugs.
13:50:54  [INFO] Sensor javabugs [dbd] (done) | time=2020ms
13:50:54  [INFO] Sensor pythonbugs [dbd]
13:50:54  [INFO] No IR files have been included for analysis.
13:50:54  [INFO] Sensor pythonbugs [dbd] (done) | time=6ms
13:50:54  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper]
13:50:54  [INFO] Available processors: 2
13:50:54  [INFO] Using 2 threads for analysis.
13:50:55  [INFO] Start fetching files for the text and secrets analysis
13:50:55  [INFO] Using Git CLI to retrieve untracked files
13:50:55  [INFO] Retrieving language associated files and files included via "sonar.text.inclusions" that are tracked by git
13:50:55  [INFO] Starting the text and secrets analysis
13:50:55  [INFO] 42 source files to be analyzed for the text and secrets analysis
13:50:56  [INFO] 42/42 source files have been analyzed for the text and secrets analysis
13:50:56  [INFO] Start fetching files for the binary file analysis
13:50:56  [INFO] There are no files to be analyzed for the binary file analysis
13:50:56  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper] (done) | time=2337ms
13:50:56  [INFO] Sensor JavaSecuritySensor [security]
13:50:56  [INFO] 29 taint analysis rules enabled.
13:50:57  [INFO] Analyzing 128 UCFGs to detect vulnerabilities.
13:51:01  [INFO] No entry points found.
13:51:01  [INFO] java security sensor: Begin: 2025-12-02T18:50:56.482595166Z, End: 2025-12-02T18:51:00.754442386Z, Duration: 00:00:04.271
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:50:56.487629291Z, End: 2025-12-02T18:50:56.923212062Z, Duration: 00:00:00.435
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:50:56.487766967Z, End: 2025-12-02T18:50:56.591779281Z, Duration: 00:00:00.104
13:51:01      Load UCFGs: Begin: 2025-12-02T18:50:56.592163579Z, End: 2025-12-02T18:50:56.922987789Z, Duration: 00:00:00.330
13:51:01    Check cache: Begin: 2025-12-02T18:50:56.923334971Z, End: 2025-12-02T18:50:56.923827323Z, Duration: 00:00:00.000
13:51:01      Load cache: Begin: 2025-12-02T18:50:56.923353670Z, End: 2025-12-02T18:50:56.923400263Z, Duration: 00:00:00.000
13:51:01    Create runtime call graph: Begin: 2025-12-02T18:50:56.924906844Z, End: 2025-12-02T18:50:57.007540733Z, Duration: 00:00:00.082
13:51:01      Variable Type Analysis #1: Begin: 2025-12-02T18:50:56.925852331Z, End: 2025-12-02T18:50:56.975075803Z, Duration: 00:00:00.049
13:51:01        Create runtime type propagation graph: Begin: 2025-12-02T18:50:56.927007872Z, End: 2025-12-02T18:50:56.962551165Z, Duration: 00:00:00.035
13:51:01        Run SCC (Tarjan) on 820 nodes: Begin: 2025-12-02T18:50:56.963453981Z, End: 2025-12-02T18:50:56.967134333Z, Duration: 00:00:00.003
13:51:01        Propagate runtime types to strongly connected components: Begin: 2025-12-02T18:50:56.967827736Z, End: 2025-12-02T18:50:56.974506490Z, Duration: 00:00:00.006
13:51:01      Variable Type Analysis #2: Begin: 2025-12-02T18:50:56.978911252Z, End: 2025-12-02T18:50:57.005909485Z, Duration: 00:00:00.026
13:51:01        Create runtime type propagation graph: Begin: 2025-12-02T18:50:56.979320598Z, End: 2025-12-02T18:50:56.992947865Z, Duration: 00:00:00.013
13:51:01        Run SCC (Tarjan) on 820 nodes: Begin: 2025-12-02T18:50:56.993207159Z, End: 2025-12-02T18:50:56.998292028Z, Duration: 00:00:00.005
13:51:01        Propagate runtime types to strongly connected components: Begin: 2025-12-02T18:50:56.998581431Z, End: 2025-12-02T18:50:57.005569373Z, Duration: 00:00:00.006
13:51:01    Load config: Begin: 2025-12-02T18:50:57.007679373Z, End: 2025-12-02T18:51:00.717407089Z, Duration: 00:00:03.709
13:51:01    Compute entry points: Begin: 2025-12-02T18:51:00.718052857Z, End: 2025-12-02T18:51:00.751340624Z, Duration: 00:00:00.033
13:51:01  [INFO] java security sensor peak memory: 702 MB
13:51:01  [INFO] Sensor JavaSecuritySensor [security] (done) | time=4284ms
13:51:01  [INFO] Sensor CSharpSecuritySensor [security]
13:51:01  [INFO] 26 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] csharp security sensor: Begin: 2025-12-02T18:51:00.759421235Z, End: 2025-12-02T18:51:00.775724023Z, Duration: 00:00:00.016
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.760251464Z, End: 2025-12-02T18:51:00.774819412Z, Duration: 00:00:00.014
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.760377804Z, End: 2025-12-02T18:51:00.760950958Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.761211847Z, End: 2025-12-02T18:51:00.774160127Z, Duration: 00:00:00.012
13:51:01  [INFO] csharp security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor CSharpSecuritySensor [security] (done) | time=18ms
13:51:01  [INFO] Sensor VbNetSecuritySensor [security]
13:51:01  [INFO] 25 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] vbnet security sensor: Begin: 2025-12-02T18:51:00.777587422Z, End: 2025-12-02T18:51:00.787605222Z, Duration: 00:00:00.010
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.778321490Z, End: 2025-12-02T18:51:00.779687009Z, Duration: 00:00:00.001
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.778447628Z, End: 2025-12-02T18:51:00.778944756Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.779176747Z, End: 2025-12-02T18:51:00.779523627Z, Duration: 00:00:00.000
13:51:01  [INFO] vbnet security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor VbNetSecuritySensor [security] (done) | time=14ms
13:51:01  [INFO] Sensor PhpSecuritySensor [security]
13:51:01  [INFO] 18 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] php security sensor: Begin: 2025-12-02T18:51:00.797055481Z, End: 2025-12-02T18:51:00.802999169Z, Duration: 00:00:00.005
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.802245585Z, End: 2025-12-02T18:51:00.802644569Z, Duration: 00:00:00.000
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.802261513Z, End: 2025-12-02T18:51:00.802436531Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.802556176Z, End: 2025-12-02T18:51:00.802614427Z, Duration: 00:00:00.000
13:51:01  [INFO] php security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor PhpSecuritySensor [security] (done) | time=11ms
13:51:01  [INFO] Sensor PythonSecuritySensor [security]
13:51:01  [INFO] 21 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] python security sensor: Begin: 2025-12-02T18:51:00.803823971Z, End: 2025-12-02T18:51:00.809227381Z, Duration: 00:00:00.005
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.804232162Z, End: 2025-12-02T18:51:00.804550292Z, Duration: 00:00:00.000
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.804242946Z, End: 2025-12-02T18:51:00.804370112Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.804443325Z, End: 2025-12-02T18:51:00.804504779Z, Duration: 00:00:00.000
13:51:01  [INFO] python security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor PythonSecuritySensor [security] (done) | time=6ms
13:51:01  [INFO] Sensor JsSecuritySensor [security]
13:51:01  [INFO] 15 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] js security sensor: Begin: 2025-12-02T18:51:00.810547765Z, End: 2025-12-02T18:51:00.812177855Z, Duration: 00:00:00.001
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.811440524Z, End: 2025-12-02T18:51:00.811821673Z, Duration: 00:00:00.000
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.811454359Z, End: 2025-12-02T18:51:00.811591342Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.811687731Z, End: 2025-12-02T18:51:00.811767424Z, Duration: 00:00:00.000
13:51:01  [INFO] js security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor JsSecuritySensor [security] (done) | time=3ms
13:51:01  [INFO] Sensor KotlinSecuritySensor [security]
13:51:01  [INFO] 28 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] kotlin security sensor: Begin: 2025-12-02T18:51:00.813007906Z, End: 2025-12-02T18:51:00.814024870Z, Duration: 00:00:00.001
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.813344134Z, End: 2025-12-02T18:51:00.813703992Z, Duration: 00:00:00.000
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.813372348Z, End: 2025-12-02T18:51:00.813508465Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.813587178Z, End: 2025-12-02T18:51:00.813654308Z, Duration: 00:00:00.000
13:51:01  [INFO] kotlin security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor KotlinSecuritySensor [security] (done) | time=2ms
13:51:01  [INFO] Sensor GoSecuritySensor [security]
13:51:01  [INFO] 9 taint analysis rules enabled.
13:51:01  [INFO] No UCFGs have been included for analysis.
13:51:01  [INFO] go security sensor: Begin: 2025-12-02T18:51:00.814838370Z, End: 2025-12-02T18:51:00.815543262Z, Duration: 00:00:00.000
13:51:01    Load type hierarchy and UCFGs: Begin: 2025-12-02T18:51:00.815036008Z, End: 2025-12-02T18:51:00.815295788Z, Duration: 00:00:00.000
13:51:01      Load type hierarchy: Begin: 2025-12-02T18:51:00.815047787Z, End: 2025-12-02T18:51:00.815157530Z, Duration: 00:00:00.000
13:51:01      Load UCFGs: Begin: 2025-12-02T18:51:00.815210175Z, End: 2025-12-02T18:51:00.815260623Z, Duration: 00:00:00.000
13:51:01  [INFO] go security sensor peak memory: 371 MB
13:51:01  [INFO] Sensor GoSecuritySensor [security] (done) | time=1ms
13:51:01  [INFO] ------------- Run sensors on project
13:51:01  [INFO] Sensor JavaProjectSensor [java]
13:51:01  [INFO] Sensor JavaProjectSensor [java] (done) | time=3ms
13:51:01  [INFO] Sensor JavaArchitectureSensor [architecture]
13:51:01  [INFO] * Protobuf reading starting | memory total=700 | free=312 | used=387 (MB)
13:51:01  [INFO] * Reading SonarArchitecture IR data from directory "/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar/architecture/java"
13:51:01  [INFO] * Files successfully loaded: "41" out of "41"
13:51:01  [INFO] * Protobuf reading complete | memory total=700 | free=292 | used=407 (MB)
13:51:01  [INFO] * Build architecture.graph.java.namespace_graph.default_perspective hierarchy graph complete (filtered=true) | memory total=700 | free=290 | used=409 (MB)
13:51:01  [INFO] * Slicing complete | memory total=700 | free=290 | used=409 (MB)
13:51:01  [INFO] * Cycle detection complete | memory total=700 | free=289 | used=410 (MB)
13:51:01  [INFO] Sensor JavaArchitectureSensor [architecture] (done) | time=621ms
13:51:01  [INFO] Sensor Zero Coverage Sensor
13:51:01  [INFO] Sensor Zero Coverage Sensor (done) | time=2ms
13:51:01  [INFO] Sensor Java CPD Block Indexer
13:51:02  [INFO] Sensor Java CPD Block Indexer (done) | time=113ms
13:51:02  [INFO] ------------- Gather SCA dependencies on project
13:51:02  [INFO] Dependency analysis skipped
13:51:02  [INFO] SCM Publisher SCM provider for this project is: git
13:51:02  [INFO] SCM Publisher 1 source file to be analyzed
13:51:02  [INFO] SCM Publisher 0/1 source files have been analyzed (done) | time=168ms
13:51:02  [WARNING] Missing blame information for the following files:
13:51:02  [WARNING]   * pom.xml
13:51:02  [WARNING] This may lead to missing/broken features in SonarQube
13:51:02  [INFO] CPD Executor 20 files had no CPD blocks
13:51:02  [INFO] CPD Executor Calculating CPD for 11 files
13:51:02  [INFO] CPD Executor CPD calculation finished (done) | time=17ms
13:51:02  [INFO] SCM revision ID '97b700acd000e788f46ab073170e5b19240ece9d'
13:51:02  [INFO] Load New Code definition
13:51:02  [INFO] Load New Code definition (done) | time=18ms
13:51:02  [INFO] SCM writing changed lines
13:51:02  [INFO] Merge base sha1: 61503bfc79587cb35934a3323b3ecb7c5823fbe8
13:51:02  [INFO] SCM writing changed lines (done) | time=350ms
13:51:02  [INFO] Analysis report generated in 627ms, dir size=950.1 kB
13:51:02  [INFO] Analysis report compressed in 164ms, zip size=488.7 kB
13:51:02  [INFO] Analysis report generated in /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar/scanner-report
13:51:03  [INFO] Analysis report uploaded in 84ms
13:51:03  [INFO] ------------- Check Quality Gate status
13:51:03  [INFO] Waiting for the analysis report to be processed (max 300s)
13:51:13  [INFO] QUALITY GATE STATUS: PASSED - View details on https://sonarqube.devops.ketteq.com/dashboard?id=disaggregation&branch=sonar-test
13:51:13  [INFO] Analysis total time: 40.852 s
13:51:13  [INFO] SonarScanner Engine completed successfully
13:51:13  [INFO] ------------------------------------------------------------------------
13:51:13  [INFO] BUILD SUCCESS
13:51:13  [INFO] ------------------------------------------------------------------------
13:51:13  [INFO] Total time:  49.131 s
13:51:13  [INFO] Finished at: 2025-12-02T18:51:13Z
13:51:13  [INFO] ------------------------------------------------------------------------
13:51:13  [INFO] [jenkins-event-spy] Generated /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven77356af3/maven-spy-20251202-185023-67213177016931601203222.log

Hi,

This is not a verbose log. I can see that you added -Dsonar.verbose=true on the analysis command line, but I also see you invoked a profile, which I can only guess overrode that? Can you run the analysis without the profile?

 
Thx,
Ann

Ran it without profile, I think logs are similar:

17:44:08  + mvn sonar:sonar -Dsonar.verbose=true -Dnexus.url=http://nexus.internal:8081 -Dsonar.host.url=http://sonarqube.internal:9000
17:44:08  Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1" 
17:44:10  [INFO] [jenkins-event-spy] Generate /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1/maven-spy-20251202-224409-89613141836599425854404.log.tmp ...
17:44:10  [INFO] Scanning for projects...
17:44:11  [INFO] 
17:44:11  [INFO] -------------------< com.ketteq.data:disaggregation >-------------------
17:44:11  [INFO] Building disaggregation ee104d016c42eedd48f410d4aa59fb61-SNAPSHOT
17:44:11  [INFO]   from pom.xml
17:44:11  [INFO] --------------------------------[ jar ]---------------------------------
17:44:13  [INFO] 
17:44:13  [INFO] --- sonar:5.1.0.4751:sonar (default-cli) @ disaggregation ---
17:44:13  [INFO] Java 21.0.4 Amazon.com Inc. (64-bit)
17:44:13  [INFO] Linux 6.1.109-118.189.amzn2023.x86_64 (amd64)
17:44:13  [INFO] User cache: /home/ec2-user/.sonar/cache
17:44:15  [INFO] Communicating with SonarQube Server 2025.4.2.112048
17:44:15  [WARNING] Use of 'sonar.login' property has been deprecated in favor of 'sonar.token' (or the env variable alternative 'SONAR_TOKEN'). Please use the latter when passing a token.
17:44:15  [INFO] JRE provisioning: os[linux], arch[x86_64]
17:44:15  [ERROR] [stderr] Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1" 
17:44:15  [ERROR] [stderr] Picked up JAVA_TOOL_OPTIONS: -Dmaven.ext.class.path="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1/pipeline-maven-spy.jar" -Dorg.jenkinsci.plugins.pipeline.maven.reportsFolder="/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1" 
17:44:16  [INFO] Starting SonarScanner Engine...
17:44:16  [INFO] Java 17.0.13 Eclipse Adoptium (64-bit)
17:44:18  [INFO] Load global settings
17:44:18  [INFO] Load global settings (done) | time=102ms
17:44:18  [INFO] Server id: 4D5C0650-AYq-ay5fIHn0VB1XJwKd
17:44:18  [INFO] Loading required plugins
17:44:18  [INFO] Load plugins index
17:44:18  [INFO] Load plugins index (done) | time=43ms
17:44:18  [INFO] Load/download plugins
17:44:18  [INFO] Load/download plugins (done) | time=114ms
17:44:18  [INFO] Loaded core extensions: developer-scanner
17:44:19  [INFO] Process project properties
17:44:19  [INFO] Process project properties (done) | time=27ms
17:44:19  [INFO] Project key: disaggregation
17:44:19  [INFO] Base dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test
17:44:19  [INFO] Working dir: /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar
17:44:19  [INFO] Load project settings for component key: 'disaggregation'
17:44:19  [INFO] Load project settings for component key: 'disaggregation' (done) | time=50ms
17:44:19  [INFO] Load project branches
17:44:19  [INFO] Load project branches (done) | time=58ms
17:44:19  [INFO] Load branch configuration
17:44:19  [INFO] Found manual configuration of branch/PR analysis. Skipping automatic configuration.
17:44:19  [INFO] Load branch configuration (done) | time=2ms
17:44:19  [INFO] Load quality profiles
17:44:19  [INFO] Load quality profiles (done) | time=147ms
17:44:19  [INFO] Auto-configuring with CI 'Jenkins'
17:44:19  [INFO] Load active rules
17:44:20  [INFO] Load active rules (done) | time=643ms
17:44:20  [INFO] Load analysis cache
17:44:20  [INFO] Load analysis cache | time=60ms
17:44:20  [INFO] Branch name: sonar-test
17:44:20  [WARNING] The property 'sonar.login' is deprecated and will be removed in the future. Please use the 'sonar.token' property instead when passing a token.
17:44:20  [INFO] Preprocessing files...
17:44:20  [INFO] 2 languages detected in 42 preprocessed files (done) | time=241ms
17:44:20  [INFO] 0 files ignored because of scm ignore settings
17:44:20  [INFO] Loading plugins for detected languages
17:44:20  [INFO] Load/download plugins
17:44:20  [INFO] Load/download plugins (done) | time=160ms
17:44:21  [INFO] Load project repositories
17:44:21  [INFO] Load project repositories (done) | time=168ms
17:44:21  [INFO] Indexing files...
17:44:21  [INFO] Project configuration:
17:44:21  [INFO] 42 files indexed (done) | time=48ms
17:44:21  [INFO] Quality profile for java: Sonar way
17:44:21  [INFO] Quality profile for xml: Sonar way
17:44:21  [INFO] ------------- Run sensors on module disaggregation
17:44:21  [INFO] Load metrics repository
17:44:21  [INFO] Load metrics repository (done) | time=39ms
17:44:23  [INFO] Sensor JavaSensor [java]
17:44:23  [INFO] Configured Java source version (sonar.java.source): 21, preview features enabled (sonar.java.enablePreview): false
17:44:23  [INFO] Server-side caching is enabled. The Java analyzer will not try to leverage data from a previous analysis.
17:44:23  [INFO] Using ECJ batch to parse 31 Main java source files with batch size 102 KB.
17:44:23  [INFO] Starting batch processing.
17:44:24  [INFO] The Java analyzer cannot skip unchanged files in this context. A full analysis is performed for all files.
17:44:34  [INFO] 90% analyzed
17:44:34  [INFO] 100% analyzed
17:44:34  [INFO] Batch processing: Done.
17:44:34  [INFO] Did not optimize analysis for any files, performed a full analysis for all 31 files.
17:44:34  [INFO] Using ECJ batch to parse 10 Test java source files with batch size 102 KB.
17:44:34  [INFO] Starting batch processing.
17:44:36  [INFO] 100% analyzed
17:44:36  [INFO] Batch processing: Done.
17:44:36  [INFO] Did not optimize analysis for any files, performed a full analysis for all 10 files.
17:44:36  [INFO] No "Generated" source files to scan.
17:44:36  [INFO] Sensor JavaSensor [java] (done) | time=13378ms
17:44:36  [INFO] Sensor JaCoCo XML Report Importer [jacoco]
17:44:36  [INFO] 'sonar.coverage.jacoco.xmlReportPaths' is not defined. Using default locations: target/site/jacoco/jacoco.xml,target/site/jacoco-it/jacoco.xml,build/reports/jacoco/test/jacocoTestReport.xml
17:44:36  [INFO] Importing 1 report(s). Turn your logs in debug mode in order to see the exhaustive list.
17:44:36  [INFO] Sensor JaCoCo XML Report Importer [jacoco] (done) | time=98ms
17:44:36  [INFO] Sensor IaC Docker Sensor [iac]
17:44:36  [INFO] 0 source files to be analyzed
17:44:36  [INFO] 0/0 source files have been analyzed
17:44:36  [INFO] Sensor IaC Docker Sensor [iac] (done) | time=172ms
17:44:36  [INFO] Sensor Java Config Sensor [iac]
17:44:36  [INFO] 0 source files to be analyzed
17:44:36  [INFO] 0/0 source files have been analyzed
17:44:36  [INFO] Sensor Java Config Sensor [iac] (done) | time=25ms
17:44:36  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend]
17:44:36  [INFO] Sensor ThymeLeaf template sensor [securityjavafrontend] (done) | time=1ms
17:44:36  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend]
17:44:36  [INFO] Sensor JavaAndroidConfigurationSensor [securityjavafrontend] (done) | time=1ms
17:44:36  [INFO] Sensor SurefireSensor [java]
17:44:36  [INFO] parsing [/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/surefire-reports]
17:44:36  [INFO] Sensor SurefireSensor [java] (done) | time=118ms
17:44:36  [INFO] Sensor Removed properties sensor [java]
17:44:36  [WARNING] Property 'sonar.jacoco.reportPath' is no longer supported. Use JaCoCo's xml report and sonar-jacoco plugin.
17:44:36  [INFO] Sensor Removed properties sensor [java] (done) | time=0ms
17:44:36  [INFO] Sensor XML Sensor [xml]
17:44:36  [INFO] 1 source file to be analyzed
17:44:36  [INFO] 1/1 source file has been analyzed
17:44:36  [INFO] Sensor XML Sensor [xml] (done) | time=219ms
17:44:36  [INFO] Sensor Serverless configuration file sensor [security]
17:44:36  [INFO] 0 Serverless function entries were found in the project
17:44:36  [INFO] 0 Serverless function handlers were kept as entrypoints
17:44:36  [INFO] Sensor Serverless configuration file sensor [security] (done) | time=4ms
17:44:36  [INFO] Sensor AWS SAM template file sensor [security]
17:44:36  [INFO] Sensor AWS SAM template file sensor [security] (done) | time=2ms
17:44:36  [INFO] Sensor AWS SAM Inline template file sensor [security]
17:44:36  [INFO] Sensor AWS SAM Inline template file sensor [security] (done) | time=2ms
17:44:36  [INFO] Sensor javabugs [dbd]
17:44:37  [INFO] Analyzing 144/479 functions to detect bugs.
17:44:39  [INFO] Sensor javabugs [dbd] (done) | time=2017ms
17:44:39  [INFO] Sensor pythonbugs [dbd]
17:44:39  [INFO] No IR files have been included for analysis.
17:44:39  [INFO] Sensor pythonbugs [dbd] (done) | time=2ms
17:44:39  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper]
17:44:39  [INFO] Available processors: 2
17:44:39  [INFO] Using 2 threads for analysis.
17:44:40  [INFO] Start fetching files for the text and secrets analysis
17:44:40  [INFO] Using Git CLI to retrieve untracked files
17:44:40  [INFO] Retrieving language associated files and files included via "sonar.text.inclusions" that are tracked by git
17:44:40  [INFO] Starting the text and secrets analysis
17:44:40  [INFO] 42 source files to be analyzed for the text and secrets analysis
17:44:41  [INFO] 42/42 source files have been analyzed for the text and secrets analysis
17:44:41  [INFO] Start fetching files for the binary file analysis
17:44:41  [INFO] There are no files to be analyzed for the binary file analysis
17:44:41  [INFO] Sensor DeveloperTextAndSecretsSensor [textdeveloper] (done) | time=2204ms
17:44:41  [INFO] Sensor JavaSecuritySensor [security]
17:44:41  [INFO] 29 taint analysis rules enabled.
17:44:41  [INFO] Analyzing 128 UCFGs to detect vulnerabilities.
17:44:45  [INFO] No entry points found.
17:44:45  [INFO] java security sensor: Begin: 2025-12-02T22:44:41.106156180Z, End: 2025-12-02T22:44:45.479267809Z, Duration: 00:00:04.373
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:41.111396401Z, End: 2025-12-02T22:44:41.493528324Z, Duration: 00:00:00.382
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:41.111471327Z, End: 2025-12-02T22:44:41.219324643Z, Duration: 00:00:00.107
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:41.219608418Z, End: 2025-12-02T22:44:41.493381711Z, Duration: 00:00:00.273
17:44:45    Check cache: Begin: 2025-12-02T22:44:41.493616650Z, End: 2025-12-02T22:44:41.494029281Z, Duration: 00:00:00.000
17:44:45      Load cache: Begin: 2025-12-02T22:44:41.493635348Z, End: 2025-12-02T22:44:41.493675760Z, Duration: 00:00:00.000
17:44:45    Create runtime call graph: Begin: 2025-12-02T22:44:41.494133750Z, End: 2025-12-02T22:44:41.681362111Z, Duration: 00:00:00.187
17:44:45      Variable Type Analysis #1: Begin: 2025-12-02T22:44:41.495591653Z, End: 2025-12-02T22:44:41.641748435Z, Duration: 00:00:00.146
17:44:45        Create runtime type propagation graph: Begin: 2025-12-02T22:44:41.496729922Z, End: 2025-12-02T22:44:41.621046320Z, Duration: 00:00:00.124
17:44:45        Run SCC (Tarjan) on 820 nodes: Begin: 2025-12-02T22:44:41.625303110Z, End: 2025-12-02T22:44:41.631495179Z, Duration: 00:00:00.006
17:44:45        Propagate runtime types to strongly connected components: Begin: 2025-12-02T22:44:41.632221567Z, End: 2025-12-02T22:44:41.641276461Z, Duration: 00:00:00.009
17:44:45      Variable Type Analysis #2: Begin: 2025-12-02T22:44:41.644437650Z, End: 2025-12-02T22:44:41.679680033Z, Duration: 00:00:00.035
17:44:45        Create runtime type propagation graph: Begin: 2025-12-02T22:44:41.644683877Z, End: 2025-12-02T22:44:41.664240550Z, Duration: 00:00:00.019
17:44:45        Run SCC (Tarjan) on 820 nodes: Begin: 2025-12-02T22:44:41.669353742Z, End: 2025-12-02T22:44:41.670891125Z, Duration: 00:00:00.001
17:44:45        Propagate runtime types to strongly connected components: Begin: 2025-12-02T22:44:41.674390884Z, End: 2025-12-02T22:44:41.679206178Z, Duration: 00:00:00.004
17:44:45    Load config: Begin: 2025-12-02T22:44:41.681620731Z, End: 2025-12-02T22:44:45.427391547Z, Duration: 00:00:03.745
17:44:45    Compute entry points: Begin: 2025-12-02T22:44:45.427921101Z, End: 2025-12-02T22:44:45.477156202Z, Duration: 00:00:00.049
17:44:45  [INFO] java security sensor peak memory: 752 MB
17:44:45  [INFO] Sensor JavaSecuritySensor [security] (done) | time=4383ms
17:44:45  [INFO] Sensor CSharpSecuritySensor [security]
17:44:45  [INFO] 26 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] csharp security sensor: Begin: 2025-12-02T22:44:45.483620858Z, End: 2025-12-02T22:44:45.484949245Z, Duration: 00:00:00.001
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.484112847Z, End: 2025-12-02T22:44:45.484609784Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.484131378Z, End: 2025-12-02T22:44:45.484328322Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.484410704Z, End: 2025-12-02T22:44:45.484548862Z, Duration: 00:00:00.000
17:44:45  [INFO] csharp security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor CSharpSecuritySensor [security] (done) | time=2ms
17:44:45  [INFO] Sensor VbNetSecuritySensor [security]
17:44:45  [INFO] 25 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] vbnet security sensor: Begin: 2025-12-02T22:44:45.485766849Z, End: 2025-12-02T22:44:45.486752669Z, Duration: 00:00:00.000
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.486130639Z, End: 2025-12-02T22:44:45.486502341Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.486150208Z, End: 2025-12-02T22:44:45.486306994Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.486368854Z, End: 2025-12-02T22:44:45.486443968Z, Duration: 00:00:00.000
17:44:45  [INFO] vbnet security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor VbNetSecuritySensor [security] (done) | time=2ms
17:44:45  [INFO] Sensor PhpSecuritySensor [security]
17:44:45  [INFO] 18 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] php security sensor: Begin: 2025-12-02T22:44:45.487473518Z, End: 2025-12-02T22:44:45.488310645Z, Duration: 00:00:00.000
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.487771598Z, End: 2025-12-02T22:44:45.488061095Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.487787907Z, End: 2025-12-02T22:44:45.487901704Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.487964685Z, End: 2025-12-02T22:44:45.488026109Z, Duration: 00:00:00.000
17:44:45  [INFO] php security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor PhpSecuritySensor [security] (done) | time=1ms
17:44:45  [INFO] Sensor PythonSecuritySensor [security]
17:44:45  [INFO] 21 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] python security sensor: Begin: 2025-12-02T22:44:45.489010276Z, End: 2025-12-02T22:44:45.489901044Z, Duration: 00:00:00.000
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.489358605Z, End: 2025-12-02T22:44:45.489640705Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.489373821Z, End: 2025-12-02T22:44:45.489487217Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.489543528Z, End: 2025-12-02T22:44:45.489602453Z, Duration: 00:00:00.000
17:44:45  [INFO] python security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor PythonSecuritySensor [security] (done) | time=2ms
17:44:45  [INFO] Sensor JsSecuritySensor [security]
17:44:45  [INFO] 15 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] js security sensor: Begin: 2025-12-02T22:44:45.490828214Z, End: 2025-12-02T22:44:45.492246359Z, Duration: 00:00:00.001
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.491689989Z, End: 2025-12-02T22:44:45.491989357Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.491706870Z, End: 2025-12-02T22:44:45.491818386Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.491889636Z, End: 2025-12-02T22:44:45.491949426Z, Duration: 00:00:00.000
17:44:45  [INFO] js security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor JsSecuritySensor [security] (done) | time=2ms
17:44:45  [INFO] Sensor KotlinSecuritySensor [security]
17:44:45  [INFO] 28 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] kotlin security sensor: Begin: 2025-12-02T22:44:45.493104618Z, End: 2025-12-02T22:44:45.494012048Z, Duration: 00:00:00.000
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.493457496Z, End: 2025-12-02T22:44:45.493748692Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.493475114Z, End: 2025-12-02T22:44:45.493589047Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.493648178Z, End: 2025-12-02T22:44:45.493706039Z, Duration: 00:00:00.000
17:44:45  [INFO] kotlin security sensor peak memory: 720 MB
17:44:45  [INFO] Sensor KotlinSecuritySensor [security] (done) | time=2ms
17:44:45  [INFO] Sensor GoSecuritySensor [security]
17:44:45  [INFO] 9 taint analysis rules enabled.
17:44:45  [INFO] No UCFGs have been included for analysis.
17:44:45  [INFO] go security sensor: Begin: 2025-12-02T22:44:45.494758551Z, End: 2025-12-02T22:44:45.495512029Z, Duration: 00:00:00.000
17:44:45    Load type hierarchy and UCFGs: Begin: 2025-12-02T22:44:45.494967282Z, End: 2025-12-02T22:44:45.495269006Z, Duration: 00:00:00.000
17:44:45      Load type hierarchy: Begin: 2025-12-02T22:44:45.494983234Z, End: 2025-12-02T22:44:45.495091770Z, Duration: 00:00:00.000
17:44:45      Load UCFGs: Begin: 2025-12-02T22:44:45.495166713Z, End: 2025-12-02T22:44:45.495228457Z, Duration: 00:00:00.000
17:44:45  [INFO] go security sensor peak memory: 721 MB
17:44:45  [INFO] Sensor GoSecuritySensor [security] (done) | time=1ms
17:44:45  [INFO] ------------- Run sensors on project
17:44:45  [INFO] Sensor JavaProjectSensor [java]
17:44:45  [INFO] Sensor JavaProjectSensor [java] (done) | time=6ms
17:44:45  [INFO] Sensor JavaArchitectureSensor [architecture]
17:44:45  [INFO] * Protobuf reading starting | memory total=947 | free=210 | used=736 (MB)
17:44:45  [INFO] * Reading SonarArchitecture IR data from directory "/home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar/architecture/java"
17:44:46  [INFO] * Files successfully loaded: "41" out of "41"
17:44:46  [INFO] * Protobuf reading complete | memory total=947 | free=190 | used=756 (MB)
17:44:46  [INFO] * Build architecture.graph.java.namespace_graph.default_perspective hierarchy graph complete (filtered=true) | memory total=947 | free=188 | used=758 (MB)
17:44:46  [INFO] * Slicing complete | memory total=947 | free=188 | used=758 (MB)
17:44:46  [INFO] * Cycle detection complete | memory total=947 | free=187 | used=759 (MB)
17:44:46  [INFO] Sensor JavaArchitectureSensor [architecture] (done) | time=496ms
17:44:46  [INFO] Sensor Zero Coverage Sensor
17:44:46  [INFO] Sensor Zero Coverage Sensor (done) | time=1ms
17:44:46  [INFO] Sensor Java CPD Block Indexer
17:44:46  [INFO] Sensor Java CPD Block Indexer (done) | time=140ms
17:44:46  [INFO] ------------- Gather SCA dependencies on project
17:44:46  [INFO] Dependency analysis skipped
17:44:46  [INFO] SCM Publisher SCM provider for this project is: git
17:44:46  [INFO] SCM Publisher 1 source file to be analyzed
17:44:46  [INFO] SCM Publisher 0/1 source files have been analyzed (done) | time=156ms
17:44:46  [WARNING] Missing blame information for the following files:
17:44:46  [WARNING]   * pom.xml
17:44:46  [WARNING] This may lead to missing/broken features in SonarQube
17:44:46  [INFO] CPD Executor 20 files had no CPD blocks
17:44:46  [INFO] CPD Executor Calculating CPD for 11 files
17:44:46  [INFO] CPD Executor CPD calculation finished (done) | time=15ms
17:44:46  [INFO] SCM revision ID '6b4d91fc445245a700f6c9bf520ba863d6ebfec7'
17:44:46  [INFO] Load New Code definition
17:44:46  [INFO] Load New Code definition (done) | time=33ms
17:44:46  [INFO] SCM writing changed lines
17:44:46  [INFO] Merge base sha1: 61503bfc79587cb35934a3323b3ecb7c5823fbe8
17:44:47  [INFO] SCM writing changed lines (done) | time=389ms
17:44:47  [INFO] Analysis report generated in 674ms, dir size=950.5 kB
17:44:47  [INFO] Analysis report compressed in 145ms, zip size=488.8 kB
17:44:47  [INFO] Analysis report generated in /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test/target/sonar/scanner-report
17:44:47  [INFO] Analysis report uploaded in 71ms
17:44:47  [INFO] ------------- Check Quality Gate status
17:44:47  [INFO] Waiting for the analysis report to be processed (max 300s)
17:44:59  [INFO] QUALITY GATE STATUS: PASSED - View details on https://sonarqube.devops.ketteq.com/dashboard?id=disaggregation&branch=sonar-test
17:44:59  [INFO] Analysis total time: 39.153 s
17:44:59  [INFO] SonarScanner Engine completed successfully
17:44:59  [INFO] ------------------------------------------------------------------------
17:44:59  [INFO] BUILD SUCCESS
17:44:59  [INFO] ------------------------------------------------------------------------
17:44:59  [INFO] Total time:  47.501 s
17:44:59  [INFO] Finished at: 2025-12-02T22:44:57Z
17:44:59  [INFO] ------------------------------------------------------------------------
17:44:59  [INFO] [jenkins-event-spy] Generated /home/ec2-user/jenkins/workspace/q-data_disaggregation_sonar-test@tmp/withMaven3a1a7ca1/maven-spy-20251202-224409-89613141836599425854404.log

Hi,

Since this is Maven, can you try it with -X on the analysis command line?

 
Thx,
Ann

Added -X, logs attached

sonarlog.txt (247.7 KB)

Hi,

Thanks for the log.

I’m not sure what’s going on with your branch and/or checkout, but we’ve got something entirely different this time:

That’s versus your previous log:

I’m guessing you made changes to the pom in the workspace to try to get me a debug log? Unfortunately, it’s the only file showing up as new.

I need to point you to the prerequisites again.

And again, what’s new is detected from the SCM data. But I see that rather than let the integration detect your branch data from the environment, you’ve manually specified it:

 
Ann