Files
Model-Optimizer/.gitlab
Keval Morabia 1306841989 Enable SonarQube Static Application Security Testing (SAST) (#1349)
Enable SonarQube as a Nvidia recommended and more comprehensive code
scanning tools compared to Bandit we currently use in pre-commit hook
(still left for now)

Tested pipeline in internal gitlab and it works and results are uploaded
in internal SonarQube website

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Added CI jobs to run SonarQube analysis and generate a vulnerability
report, with scheduled and branch-triggered runs.
* Configured scans to preserve full git history, use caching, and
auto-cancel interruptible runs.
* Added an ignore rule to exclude generated analysis artifacts from
version control.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Keval Morabia <28916987+kevalmorabia97@users.noreply.github.com>
2026-04-28 00:34:27 +05:30
..