# SonarQube

EvoHub receives SonarQube analyses through a **webhook**. A failed quality gate on the main branch opens an alert listing the conditions that failed; the next passing gate resolves it.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **SonarQube**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Generate a signing secret
Open the integration and, under **Signing secret**, click **Generate secret**. Copy it — it is shown once.
### Add the webhook
In SonarQube, open **Project Settings → Webhooks** (or **Administration → Configuration → Webhooks** for every project) and click **Create**. Set **URL** to your webhook URL and **Secret** to the signing secret.
:::

## What pages

| Analysis | EvoHub |
| --- | --- |
| Quality gate `ERROR` on the main branch | opens a **medium** alert |
| Quality gate `OK` on the main branch | resolves it |
| Pull request or other-branch analysis | nothing |
| Analysis without a quality gate (the background task failed) | nothing |

On editions without branch analysis there is only the main branch, and every analysis counts.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | *Quality gate failed:* and the project name and branch. |
| Description | Each failed condition: the metric, its value and the threshold it crossed. |
| Labels | `project`, `branch`, `quality_gate`, `revision`, and `url` — the project or branch dashboard. |

## Resolve and deduplication

An alert is identified by the project key and branch. While it is open, another failed analysis is recorded as **Retriggered** instead of paging again.

## Signature

With a signing secret set, every delivery must carry a valid `X-Sonar-Webhook-HMAC-SHA256` header (an HMAC-SHA256 of the body). Anything else is refused with `403` and opens nothing. See [Signing secrets](https://docs-dev.evohub.io/integrations-overview.md#signing-secrets).

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [GitHub](https://docs-dev.evohub.io/github.md)
- [GitLab](https://docs-dev.evohub.io/gitlab.md)
