[Experiment] [DX-4553] CRE Test Speedups - #23232
Quality Gate failed
Failed conditions
7 Security Hotspots
C Security Rating on New Code (required ≥ A)
See analysis details on SonarQube
Catch issues before they fail your Quality Gate with our IDE extension
SonarQube for IDE
Annotations
Check warning on line 199 in .github/workflows/cre-regression-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Dependency versions are not predictable. Use a lock-file enforcing command instead.
[S8545] Go dependencies should be locked to verified versions
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=b0961da7-8046-4101-99e1-fda8604335a7&open=b0961da7-8046-4101-99e1-fda8604335a7
Check warning on line 537 in .github/workflows/integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=75cffe93-9151-4902-8573-517698c45b50&open=75cffe93-9151-4902-8573-517698c45b50
Check warning on line 237 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=c034d670-7b11-4469-aac2-7e7811c3acc5&open=c034d670-7b11-4469-aac2-7e7811c3acc5
Check warning on line 677 in .github/workflows/integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Only pass required secrets to this workflow.
[S7635] Passing the full secrets context to reusable workflows is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=3fe3a40f-f3fe-4a6f-a3a1-70c5af1f6624&open=3fe3a40f-f3fe-4a6f-a3a1-70c5af1f6624
Check warning on line 73 in system-tests/tests/smoke/cre/cre_suite_test.go
cl-sonarqube-production / SonarQube Code Analysis
Refactor this method to reduce its Cognitive Complexity from 57 to the 30 allowed.
[S3776] Cognitive Complexity of functions should not be too high
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=e54cd2bd-b0e3-494d-8dc3-5ae5d7fbe27e&open=e54cd2bd-b0e3-494d-8dc3-5ae5d7fbe27e
Check warning on line 131 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=d1e198a7-16dc-4e3e-900e-dc2a0b52271c&open=d1e198a7-16dc-4e3e-900e-dc2a0b52271c
Check warning on line 187 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Dependency versions are not predictable. Use a lock-file enforcing command instead.
[S8545] Go dependencies should be locked to verified versions
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=8b9d90d0-19f9-45d3-8a07-51f18c2035b0&open=8b9d90d0-19f9-45d3-8a07-51f18c2035b0
Check warning on line 635 in .github/workflows/integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Dependency versions are not predictable. Use a lock-file enforcing command instead.
[S8545] Go dependencies should be locked to verified versions
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=df89d147-13f0-4ed5-9bd6-820529b019de&open=df89d147-13f0-4ed5-9bd6-820529b019de
Check warning on line 136 in .github/workflows/integration-in-memory-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=c6dbc746-c03e-48df-a77a-317c9e4b376b&open=c6dbc746-c03e-48df-a77a-317c9e4b376b
Check warning on line 39 in .github/workflows/run-nightly-in-memory-integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=be3d355b-5079-47f6-bfcc-dae176d6d9f8&open=be3d355b-5079-47f6-bfcc-dae176d6d9f8
Check warning on line 104 in .github/workflows/integration-in-memory-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23232&issues=3a010881-a06a-404a-8dcd-0b9a167e80b8&open=3a010881-a06a-404a-8dcd-0b9a167e80b8