Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SonarScanner for .NET 10

An optimized, CI-ready Docker image with SonarScanner for .NET preinstalled, built on the official .NET 10 SDK (GA) base image.

This image is designed for static code analysis of .NET projects using SonarQube or SonarCloud in CI/CD pipelines.


🎯 Purpose

This image exists to provide a consistent, fast, and reproducible Sonar analysis environment across multiple repositories and CI systems.

Instead of installing .NET SDK and SonarScanner on every pipeline run, teams can reuse this image as a golden CI utility image.


🔧 What's Included

  • .NET SDK 10.0 (GA, stable)
  • SonarScanner for .NET 11.3.0 (dotnet-sonarscanner)
  • Non-root default user (sonar, UID 1001)
  • Official Microsoft Ubuntu-based image
  • Multi-architecture support

⚠️ This image is intended only for CI/static analysis, not for production runtimes.


📦 Image Information

  • Docker Hub:
    Docker Hub

  • Source Repository:
    GitHub

  • Base Image:
    mcr.microsoft.com/dotnet/sdk:10.0

  • Architectures:

    • linux/amd64
    • linux/arm64

Image Tags

Image tag .NET SDK SonarScanner for .NET
6.2.0 10.0 6.2.0
11.3.0 10.0 11.3.0
latest 10.0 11.3.0

🚀 Usage

1️⃣ Docker CLI (Local or CI)

docker run --rm \
  -v "$(pwd):/workspace" \
  aloknecessary/sonar-dotnet-v10.0:latest \
  dotnet sonarscanner

2️⃣ GitHub Actions Example

Using This Image in GitHub Actions

You can use this image directly in your GitHub Actions workflow to run SonarQube or SonarCloud analysis on .NET projects.

This image already contains:

  • .NET SDK 10
  • SonarScanner for .NET

No additional setup is required.


Example: SonarQube / SonarCloud Scan

name: Sonar Analysis

on:
  push:
    branches:
      - main
  pull_request:

jobs:
  sonar:
    runs-on: ubuntu-latest

    steps:
      - name: Checkout source
        uses: actions/checkout@v7

      - name: Run SonarScanner using custom image
        uses: docker://aloknecessary/sonar-dotnet-v10.0:latest
        with:
          args: >
            dotnet sonarscanner begin
            /k:"my-project-key"
            /d:sonar.host.url=${{ secrets.SONAR_HOST_URL }}
            /d:sonar.login=${{ secrets.SONAR_TOKEN }}

      - name: Build project
        run: dotnet build

      - name: Complete Sonar analysis
        uses: docker://aloknecessary/sonar-dotnet-v10.0:latest
        with:
          args: >
            dotnet sonarscanner end
            /d:sonar.login=${{ secrets.SONAR_TOKEN }}

Workspace Permissions

The image runs as the non-root sonar user (UID 1001). A mounted workspace may have ownership or permission settings that prevent writes.

If your runner has this issue, explicitly run the container as root:

docker run --rm --user 0 \
  -v "$(pwd):/workspace" \
  -w /workspace \
  aloknecessary/sonar-dotnet-v10.0:latest

For a GitHub Actions container job:

container:
  image: aloknecessary/sonar-dotnet-v10.0:latest
  options: --user 0

About

A production-ready, multi-architecture Docker image for running SonarQube analysis on .NET v10 projects, preloaded with all required tooling to eliminate repetitive setup in CI pipelines.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages