Skip to content

fix(security): remediate SonarQube vulnerabilities#82

Open
devin-ai-integration[bot] wants to merge 2 commits intomainfrom
devin/1770237078-sonarqube-remediation
Open

fix(security): remediate SonarQube vulnerabilities#82
devin-ai-integration[bot] wants to merge 2 commits intomainfrom
devin/1770237078-sonarqube-remediation

Conversation

@devin-ai-integration
Copy link

@devin-ai-integration devin-ai-integration bot commented Feb 4, 2026

Closes: N/A (SonarQube remediation)

Summary

This PR addresses SonarQube issues in pkg/github/pullrequests.go:

S1192 - Duplicated String Literals (3 issues)

  • Defined package-level constants for repeated error messages:
    • errFailedToGetPullRequest (was duplicated 4 times)
    • errFailedToGetCurrentUser (was duplicated 3 times)
    • errFailedToGetLatestReviewForCurrUser (was duplicated 3 times)

S3776 - Cognitive Complexity (1 issue)

  • Simplified GetPullRequestFiles by using existing MarshalledTextResult utility instead of manual JSON marshaling

Review Checklist

  • Confirm string constant replacements don't change error message content
  • Verify format string changes from "failed to get pull request: %s" to "%s: %s", errFailedToGetPullRequest produce identical output
  • Check that MarshalledTextResult handles marshaling errors appropriately (it returns an error result on failure)

Alternatives Considered

Initially extracted helper functions (extractPullRequestFilesParams, fetchPullRequestFiles) to reduce cognitive complexity, but this triggered SonarCloud duplication warnings (17.4% duplication on new code). Reverted to inline parameter extraction while keeping the MarshalledTextResult simplification.


Link to Devin run: https://app.devin.ai/sessions/5e198d746b8c41219984d3af0e6df8d2
Requested by: @parkerduff

- Define constants for duplicated string literals:
  - errFailedToGetPullRequest
  - errFailedToGetCurrentUser
  - errFailedToGetLatestReviewForCurrUser
- Refactor GetPullRequestFiles to reduce cognitive complexity:
  - Extract parameter extraction into extractPullRequestFilesParams
  - Extract API call into fetchPullRequestFiles helper
  - Use MarshalledTextResult for response marshaling

Addresses SonarQube issues:
- S1192: Duplicated string literals (3 issues)
- S3776: Cognitive complexity too high (1 issue)

Co-Authored-By: parker.duff@codeium.com <pwjduff@gmail.com>
@devin-ai-integration
Copy link
Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

- Reverted GetPullRequestFiles to inline parameter extraction
- Kept constants for S1192 fix (duplicated string literals)
- Kept MarshalledTextResult usage for cleaner marshaling
- Removed pullRequestFilesParams struct and helper functions

Co-Authored-By: parker.duff@codeium.com <pwjduff@gmail.com>
@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 4, 2026

Quality Gate Failed Quality Gate failed

Failed conditions
63.2% Duplication on New Code (required ≤ 3%)
C Maintainability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants