Introduction

The plugin-based architecture of DeepSeek Harness (DSH) allows agents to obtain information through external APIs. If you want agents to directly query data from SonarQube Community Build, the dsh-sonarqube plugin provides a set of read-only tools. It uses SonarQube’s Web API to let agents view metrics such as quality gates, code issues, security hotspots, and code coverage, without modifying SonarQube’s state.

Plugin Positioning

This plugin is maintained by maxmilian, released under the MIT license, and categorized as an online tool. Its core value is that it provides a set of read-only interfaces, allowing agents to “see” code quality reports and thereby assist in decision-making or report generation.

Core Features

The plugin provides the following tools, and all operations are read-only:

  1. sonarqube_system_status: Reads instance status and version information.
  2. sonarqube_quality_gate: Reads quality gate results for a specified project, branch, or Pull Request.
  3. sonarqube_search_issues: Searches issues by type, severity, status, branch, or Pull Request.
  4. sonarqube_search_hotspots: Searches security hotspots by status, branch, or Pull Request.
  5. sonarqube_get_hotspot: Reads the full detailed information of a single security hotspot.
  6. sonarqube_get_measures: Reads coverage, duplication rate, issue count, hotspot count, or metrics selected by the caller.

Installation and Activation

You can install the plugin from the GitHub source using the following command:

dsh plugin --profile web add github:maxmilian/dsh-sonarqube#PINNED_COMMIT

After installation, the corresponding DSH profile must be restarted. The installation command automatically builds dependencies (using Bun); ensure you have permission to run this build script.

Configuration

The plugin depends on the SonarQube URL and authentication token. It is recommended to configure credentials through environment variables to avoid exposing sensitive information in plaintext in a configuration file:

export SONARQUBE_URL='https://sonarqube.example.com'
export SONARQUBE_TOKEN='your-token'

If you must set them in a configuration file, use cordis.patch.yml. The configuration priority is that plugin configuration takes precedence over environment variables:

Configuration Item Environment Variable Fallback Default Value
baseUrl SONARQUBE_URL Required
token SONARQUBE_TOKEN Required
requestTimeoutMs None 30000
maxResponseBytes None 5242880

Typical Usage

In a conversation, you can directly invoke the above tools. For example:

  • Query a project quality gate: Use sonarqube_quality_gate for project acme-api on branch main.
  • Search for issues: Search open CRITICAL issues in acme-api, 50 per page.
  • Retrieve metrics: Get coverage and duplicated_lines_density for acme-api.
  • View hotspot details: Show the full Security Hotspot with key AX_example.

Note that the branch and pull_request parameters are mutually exclusive. The search page size is limited to 1-100, and page × page_size must not exceed 10,000.

Notes

  1. Read-only limitations: The current version (0.1) does not support modifying issues or hotspots or performing actions such as confirming or resolving them.
  2. Security: The plugin authenticates with Authorization: Bearer ... and never exposes the token in returned results or logs.
  3. TLS limitations: v0.1 does not support disabling TLS verification or bypassing self-signed certificates. If SonarQube uses self-signed certificates, the certificate issue must be handled in advance.

Summary

dsh-sonarqube is a SonarQube query plugin for DeepSeek Harness. Through a standard set of read-only tools, it allows agents to seamlessly access code quality data, making it suitable for scenarios such as code review assistance and quality report generation.

Project address: https://github.com/maxmilian/dsh-sonarqube