# ruleid: detected-sonarqube-docs-api-key
SONARQUBE=5eeee8e4deeee2dbfeeeedbeeeec37b7eeeea7b9
# ruleid: detected-sonarqube-docs-api-key
sonar.login=e884618bb0f2ca8744f5b5e0e6f9d2f61bce7e8f
# ruleid: detected-sonarqube-docs-api-key
sonar.token: "1234567890abcdef1234567890abcdef12345678"
# ruleid: detected-sonarqube-docs-api-key
SONAR_TOKEN = abcdef01234567890abcdef01234567890abcdef

# The following are NOT SonarQube API keys — a 40-char git commit SHA or an
# image digest that merely co-occurs with the word "sonar". The old
# `sonar.{0,50}…[0-9a-f]{40}` regex false-positived on all of these.
# ok: detected-sonarqube-docs-api-key
uses: SonarSource/sonarqube-scan-action@713881670b6b3676cda39549040e2d88c70d582e
# ok: detected-sonarqube-docs-api-key
uses: SonarSource/sonarqube-quality-gate-action@cf038b0e0cdecfa9e56c198bbb7d21d751d62c3b
# ok: detected-sonarqube-docs-api-key
image: sonarqube:community@sha256:160bd2f6a3485bd09b655ef22dd63c02bd1fa7ba82aa5d9973fd010b8bcca0b3
# ok: detected-sonarqube-docs-api-key
pkg:githubactions/SonarSource/sonarqube-scan-action@713881670b6b3676cda39549040e2d88c70d582e
