Below you will find pages that utilize the taxonomy term “vmvarela”
January 13, 2026
SonarQube Community to GitHub Security Tab (SARIF)
Version updated for https://github.com/vmvarela/sonarqube-ce-sarif-action to version v1.0.0.
This action is used across all versions by ? repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates SonarQube Community Edition (CE) with GitHub by converting SonarQube analysis results into SARIF format, enabling PR decoration, inline annotations, and integration with the GitHub Security Tab. It automates the process of surfacing SonarQube issues within GitHub’s user interface, providing developers with actionable insights directly in pull requests, check summaries, and the Security Tab.
January 5, 2026
SonarQube Community to GitHub Security Tab (SARIF)
Version updated for https://github.com/vmvarela/sonarqube-ce-sarif-action to version v0.3.1.
This action is used across all versions by ? repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates SonarQube Community Edition (CE) with GitHub, enabling features like pull request (PR) decoration, inline code annotations, issue summaries, and GitHub Security Tab integration that are typically unavailable in the CE version. It automates the process of converting SonarQube scan results into SARIF format, providing actionable insights and better visibility of code quality and security issues directly within the GitHub interface.
January 2, 2026
SonarQube Community to GitHub Security Tab (SARIF)
Version updated for https://github.com/vmvarela/sonarqube-ce-sarif-action to version v0.3.0.
This action is used across all versions by ? repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates SonarQube Community Edition with GitHub by converting SonarQube scan results into SARIF format and uploading them to the GitHub Security Tab. It automates PR feedback through inline annotations, check summaries, and issue tracking in GitHub’s Security Tab, addressing the lack of native integration in SonarQube CE.