Core Concepts
Administering quality profiles in SonarQube
This course explains how SonarQube quality profiles determine your organization's coding and security standards, empowering teams to set and maintain consistent practices across all projects. You'll learn how to tailor these standards using custom quality profiles to ensure reliable and secure code throughout your development work.
Transcript
(music) (pulse) (chime) Welcome! SonarQube quality profiles are how you define your organization's coding and security standards. They empower teams to set and maintain consistent practices across all projects. With custom quality profiles, you can tailor these standards to match your specific needs, ensuring reliable and secure code throughout your development work. Let's get started! In this video, you’ll learn what a quality profile is, how to create a custom quality profile, and how to apply a quality profile to your SonarQube projects. You'll see the demonstration in SonarQube Cloud; however, the process is nearly identical in SonarQube Server. So, what are quality profiles? Quality profiles define the set of Sonar rules to be applied during code analysis. Each language has its own built-in Sonar way quality profile in SonarQube, which includes recommended rules and serves as a great starting point for enforcing coding standards. It’s possible that you’ll need to make some adjustments to your quality profiles due to specific project needs, such as activating or deactivating rules. Since the built-in Sonar way profiles can't be changed, you can create a custom quality profile. To create or manage a custom quality profile, you must have the Administer Quality Profiles permission at the global or organization level. This permission is found under Administration> Permissions, where you can confirm it's checked for your user or group. Let's go into the Quality profiles tab to explore the different ways you can create a custom quality profile. First, you can extend an existing quality profile, which duplicates it and keeps its inheritance. You can copy an existing quality profile, which duplicates the profile without keeping its inheritance. And, finally, you can create a new quality profile. Let’s create a new Java custom quality profile and extend it from the Sonar way. Click Create to begin. Give your profile a name, and for the language, select Java from the drop-down menu. Next, to apply SonarQube's recommended rules, select the Sonar way profile as the parent to use as a baseline. Click Create to generate the profile. Now, let's customize the Active rules list by activating a specific rule, like one for copyright and license headers, which are often a security or compliance need. On the profile page, click Activate More. Type Track lack of copyright and license headers into the Search bar. Once you find the rule, click Activate. Review its default parameters, which are typically sufficient. Then, click Activate again to confirm. That rule is now active in your custom profile. To confirm this, go back to your profile's main page. In the Inheritance section, click the hyperlink that displays the number of Active rules to see a full list of the rules inherited from the Sonar way default, plus the new rule. From this list, you can also easily change a rule's parameters if you need to adjust its thresholds or deactivate a rule if it's no longer relevant for your team. Next, you can associate a specific quality profile with a project. In the Quality profiles tab, locate the quality profile. Then, in the Projects section of the quality profile, select Change Projects. You can filter the project list by using the Search field, or by selecting one of the available tabs. For example, if you want to apply the quality profile to all projects then select the All tab. You can use Bulk Change to select all projects or select desired projects individually. When you're finished, select Close. Your quality profile has now been assigned to the project. This custom profile will take effect the next time you run a code analysis. Finally, let’s review a few best practices for managing quality profiles. Prioritize high-impact rules. Focus on Blocker, Critical, Security, and Bug rules, ensuring they fail the quality gate on new code for immediate fixes. Review and update regularly. Periodically, update profiles to match evolving standards and new SonarQube rules. Set a good baseline quality profile. If Sonar way isn’t suitable, create a custom baseline profile for your teams to build upon. In conclusion, by applying these best practices, you can effectively define and maintain your organization's code quality and security standards, ensuring cleaner, more reliable code. And that’s a wrap! See our additional videos to dive deeper into Sonar topics!