Hi there
i am investigating a convenient
solution how to make pom.xml, *.gradle, package-json.lock part of sonar.sources.
Considering that there are multiple ways to configure the scanner context, which one would you use to reduce the configuration burden on each team?
Background:
We are working with OWASP dependency-check(-plugin) and here i just found this little reminder:
This plugin tries to add SonarQube issues to your project configuration files (e.g. pom.xml, *.gradle, package-json.lock). Please make sure,
that these files are part of sonar.sources
.
4sakeofbrevity: Consider me using up to date versions of $things (oh, nvm, edit: in SQ Server)
cheers
Daniel