Update Harness CI - #185
Quality Gate failed
Failed conditions
0.0% Coverage on New Code (required ≥ 80%)
Annotations
Check failure on line 354 in src/__tests__/offline/browser.spec.js
sonarqube-pull-requests / SonarQube Code Analysis
Refactor this code to not nest functions more than 4 levels deep.
[S2004] Functions should not be nested too deeply
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=f532355d-9ce4-4ce8-8bd7-efe8813802dd&open=f532355d-9ce4-4ce8-8bd7-efe8813802dd
Check warning on line 27 in .github/workflows/update-notice-year.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=0d5df086-912e-4eca-9db9-a973f098ca72&open=0d5df086-912e-4eca-9db9-a973f098ca72
Check warning on line 92 in .github/workflows/ci-cd.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=5e7d0364-05cf-48ba-a5f8-01ab47031b9d&open=5e7d0364-05cf-48ba-a5f8-01ab47031b9d
Check warning on line 19 in .github/workflows/ci-cd.yml
sonarqube-pull-requests / SonarQube Code Analysis
Move this read permission from workflow level to job level.
[S8264] Read permissions should be defined at the job level
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=202b0aab-0aab-4160-ac57-d567c177266e&open=202b0aab-0aab-4160-ac57-d567c177266e
Check warning on line 20 in .github/workflows/ci-cd.yml
sonarqube-pull-requests / SonarQube Code Analysis
Move this write permission from workflow level to job level.
[S8233] Write permissions should be defined at the job level
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=fd12fef4-e136-466d-91b6-c5f7de26e3c7&open=fd12fef4-e136-466d-91b6-c5f7de26e3c7
Check warning on line 37 in .github/workflows/ci-cd.yml
sonarqube-pull-requests / SonarQube Code Analysis
Omitting "--ignore-scripts" can lead to the execution of shell scripts. Make sure it is safe here.
[S6505] Allowing shell scripts execution during package installation is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=073896ba-8e47-429c-aee6-9d7110620b3f&open=073896ba-8e47-429c-aee6-9d7110620b3f
Check warning on line 53 in .github/workflows/sonar-scan.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=e0d1dcac-485d-4931-a7c0-bcb06e5e6ece&open=e0d1dcac-485d-4931-a7c0-bcb06e5e6ece
Check warning on line 41 in .github/workflows/update-notice-year.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=a5c392a5-db40-48d2-a4be-810daa671cd9&open=a5c392a5-db40-48d2-a4be-810daa671cd9
Check warning on line 131 in .github/workflows/ci-cd.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=f24501bf-095c-48f4-8720-a92855556be8&open=f24501bf-095c-48f4-8720-a92855556be8
Check warning on line 39 in .github/workflows/sonar-scan.yml
sonarqube-pull-requests / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=12437986-85d9-4b94-b929-e57b83bdbece&open=12437986-85d9-4b94-b929-e57b83bdbece
Check warning on line 29 in .github/workflows/sonar-scan.yml
sonarqube-pull-requests / SonarQube Code Analysis
Omitting "--ignore-scripts" can lead to the execution of shell scripts. Make sure it is safe here.
[S6505] Allowing shell scripts execution during package installation is security-sensitive
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=dded4b87-aac3-45ec-a25a-a034952ee9b0&open=dded4b87-aac3-45ec-a25a-a034952ee9b0
Check failure on line 358 in src/__tests__/offline/browser.spec.js
sonarqube-pull-requests / SonarQube Code Analysis
Refactor this code to not nest functions more than 4 levels deep.
[S2004] Functions should not be nested too deeply
See more on https://sonar.harness.io/project/issues?id=javascript-browser-client&pullRequest=185&issues=d6266436-0f8e-499c-855c-d4c549a2217f&open=d6266436-0f8e-499c-855c-d4c549a2217f