Why does SonarCloud add comments for lines of code that have not changed? I integrated SonarCloud via Azure Devops. It scans for each PullRequest with Azure Pipeline and adds the findings as comments. But it adds comments for the unchanged lines of code.
This is a problem for our team. The appearance of codes that are not in development makes our SonarCloud unusable for PullRequest.
A developer changes 1 line in a file but leaves 10-15 comments. It’s bad advice for the developer to comment outside of the code he submitted. How do we fix this?
This sounds like a problem with the identification of new code. Assuming you haven’t disabled SCM detection, then you should make sure that
The pull request source branch is checked out in the local
The pull request source branch is checked out in the local repository.
The branch being targeted by the pull request is fetched and present in the local repository.
The analysis is being run on a local repository with valid repository metadata (e.g. the .git folders have not been removed). Avoid any attempt at previewing the merge or actions involving your main branch.
The code in the local repository matches the code in the remote repository (e.g once a PR is issued, no code is added to the local branch on the CI side before analysis).
Yes, I’m sure of these. There are 35 repositories and all of them have the same problem. For example, I change 1 line of code in the UserService.cs file, but it adds 20-25 comments in the PR. The findings it finds are correct, but it should only show them within the line or method I changed.
Thanks for your pipeline code. What I’m actually looking for is what’s output to stdout when the job runs. I want the logging that comes out of the job, not the configuration that goes into it.