Hello dear Sonar Team,
- GitHub Enterprise
- Azure DevOps
- Scanner command should not be relevant
- Languages of the repository: Scala
- Private instance
- We have a quality gate in place, that explicitly differentiates between New Code checks and Overall code checks, as we wanted to also improve the quality of the legacy code, especially for Security and Reliability rating. However the PRs are passing, even if I can see on the Overview tab, that the main branch analysis failed. My expectation would be that all Hotspot are being reviewed and the same with the Reliability. The Reliability Rating shows B, but the quality gate is configured to “worse than A”. We evaluate the status of the quality via the GitHub check.
The quality gate for new code is working as expected, for example when code coverage is below the configured threshold.
Do I have wrong expectations?
Thanks,
Andre