Fix Sonar analyzer findings - #55
Conversation
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Limit details: You’ve used all 10 included reviews currently available. 📝 WalkthroughWalkthroughThe change forwards the client stopping token to Lua module registration, adds test coverage for that behavior, and updates benchmark discovery to use a namespaced entry point. ChangesLua module lifecycle
Benchmark entry-point discovery
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
|



Cause
The post-merge Sonar run 35645780134 reported one S8949 finding in
LuaModuleLifecyclebecause module registration omitted its available cancellation token, and four S3903 findings because the benchmark helper types were declared in the global namespace.Fix
ICheatEngineClient.StoppingintoILuaClient.RegisterModule, so activation-time module registration observes shutdown cancellation before it reserves or dispatches work.BenchmarkEntryPoint,BenchmarkArtifactsDirectory,BenchmarkInvocation, andBenchmarkSummaryExtensionsintoCheatEngine.Client.Benchmarks; discovery still targets the same executing assembly.Validation
dotnet restore CheatEngine.Client.slnx --locked-modedotnet build CheatEngine.Client.slnx --configuration Release --no-restore --no-incremental --disable-build-servers --warnaserror(0 warnings, 0 errors)LuaModuleLifecycleForwardsTheClientStoppingTokenToRegistrationdotnet pack CheatEngine.Client.slnx --configuration Release --no-build --no-restore./eng/Invoke-PackageSmoke.ps1 -PackageSource ./artifacts/packages./eng/Invoke-TemplateSmoke.ps1 -PackageSource ./artifacts/packageswin-x64publish and probe executionLocal Sonar submission was not possible because neither
SONAR_TOKENnordotnet-sonarscanneris available in the workstation environment; the PR Sonar workflow remains the authoritative analysis.Summary by CodeRabbit
Bug Fixes
Tests