Skip to content

👷(ci) run the static checks before a run is approved - #1594

Closed
davd-gzl wants to merge 16 commits into
suitenumerique:mainfrom
davd-gzl:fix/checks-for-outside-contributors
Closed

👷(ci) run the static checks before a run is approved#1594
davd-gzl wants to merge 16 commits into
suitenumerique:mainfrom
davd-gzl:fix/checks-for-outside-contributors

📌(ci) pin the node the format check runs on

be3f7a6
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Aug 14, 2026 in 46s

Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 121 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJo&open=AaABAC0VkdcfuurrCTJo&pullRequest=1594

Check warning on line 78 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJd&open=AaABAC0VkdcfuurrCTJd&pullRequest=1594

Check warning on line 39 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJW&open=AaABAC0VkdcfuurrCTJW&pullRequest=1594

Check failure on line 97 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJh&open=AaABAC0VkdcfuurrCTJh&pullRequest=1594

Check warning on line 101 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJj&open=AaABAC0VkdcfuurrCTJj&pullRequest=1594

Check warning on line 240 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJv&open=AaABAC0VkdcfuurrCTJv&pullRequest=1594

Check warning on line 76 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJb&open=AaABAC0VkdcfuurrCTJb&pullRequest=1594

Check warning on line 103 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJm&open=AaABAC0VkdcfuurrCTJm&pullRequest=1594

Check warning on line 208 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJp&open=AaABAC0VkdcfuurrCTJp&pullRequest=1594

Check failure on line 71 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJZ&open=AaABAC0VkdcfuurrCTJZ&pullRequest=1594

Check warning on line 103 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJl&open=AaABAC0VkdcfuurrCTJl&pullRequest=1594

Check warning on line 237 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJt&open=AaABAC0VkdcfuurrCTJt&pullRequest=1594

Check warning on line 101 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJk&open=AaABAC0VkdcfuurrCTJk&pullRequest=1594

Check failure on line 227 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJq&open=AaABAC0VkdcfuurrCTJq&pullRequest=1594

Check warning on line 332 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJ0&open=AaABAC0VkdcfuurrCTJ0&pullRequest=1594

Check warning on line 99 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJi&open=AaABAC0VkdcfuurrCTJi&pullRequest=1594

Check warning on line 80 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJg&open=AaABAC0VkdcfuurrCTJg&pullRequest=1594

Check warning on line 43 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Lifecycle scripts are enabled by default in Yarn v2+.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJY&open=AaABAC0VkdcfuurrCTJY&pullRequest=1594

Check warning on line 294 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJy&open=AaABAC0VkdcfuurrCTJy&pullRequest=1594

Check warning on line 121 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJn&open=AaABAC0VkdcfuurrCTJn&pullRequest=1594

Check warning on line 311 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJz&open=AaABAC0VkdcfuurrCTJz&pullRequest=1594

Check warning on line 39 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJX&open=AaABAC0VkdcfuurrCTJX&pullRequest=1594

Check warning on line 73 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJa&open=AaABAC0VkdcfuurrCTJa&pullRequest=1594

Check warning on line 240 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJu&open=AaABAC0VkdcfuurrCTJu&pullRequest=1594

Check warning on line 280 in .github/workflows/build-and-test.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=suitenumerique_meet&issues=AaABAC0VkdcfuurrCTJw&open=AaABAC0VkdcfuurrCTJw&pullRequest=1594