9 ms·
Sonar is destroying my job and it's driving me to despair
- deleted 2y ago[deleted]
- dexwiz 2y agoNo matter the industry, it sucks to have someone managing by dashboard. In classic post modernism, the signifier replaces the signified. If anything, it’s a great signal to the employee that it’s time to start looking elsewhere.
- shrimp_emoji 2y agoAre flies that evolve to look like bees to ward off predators postmodern? It just seems like game theory.
- dexwiz 2y agoNo, that is convergent evolution. A more apt comparison would be selection of secondary sexual traits that no longer correspond to fitness. https://en.wikipedia.org/wiki/Signified_and_signifier https://en.wikipedia.org/wiki/Signified_and_signifier
- jjmarr 2y agoI don't get why people hate on post-structuralism. The process of reality getting abstracted to the point abstractions stop being representative of reality is extremely common in software engineering. https://en.wikipedia.org/wiki/Hyperreality https://en.wikipedia.org/wiki/Hyperreality A hyperreal workplace is one where representations of reality take precedence over reality itself, and the reality of a situation ceases to have meaning. i.e. One where people chase metrics for the sake of metrics, instead of understanding that issue count is supposed to reflect the underlying code quality, and code quality should always take priority over the representation. The broader philosophical context is relevant because it shows the broader cultural problem instead of assuming the issue is limited to a single tool.
- pdonis 2y ago> I don't get why people hate on post-structuralism. Because, rather than recognize that overdoing abstractions is a thing and reminding people that there is always reality out there that won't bend to your wishes, post-modernism (which is the term the GP used) tells people that there is no reality out there, it's all just human-created abstractions, and anyone who tries to push back because reality is just insufficiently post-modernist.
- orwin 2y agoThat's typically _not_ what post-modernism is, that's at best a misunderstanding, but more likely a strawman. The only point on which all post-modernists agree is a refutation of meta-narratives (and to be explicit: "here is no reality out there, it's all just human-created abstractions" is a meta-narrative). A very, very charitable interpretation is that you are maybe conflating it with Frankfurt School of critical theory, because it is also somewhat used/based on psychoanalysis (sigh) (latest postmodernists use psychoanalysis way less, also post-modernism isn't built on it, contrary to critical theory). Postmodernism is mostly post-marxism though, while critical theory is mostly neo-marxist imho (also, i don't want to be too critical of Frankfurt's school, i think most of their bad rep is caused by bad vulgarization/pop-science, most critics i read don't seems to understand why it's wrong either). I do think that the reason most people conflate the two is because of an idiotic canadian psychoanalyst who can't read (or at least, can't understand what he read), who _clearly_ has no degree in literature or philosophy, and try to appear smarter than he is. He invent citations of the books, and sometime state that Derrida mean something when Derrida hismself wrote the opposite. 8th grader would do better and their reading comprehension assignment. He is wrong. Read and think by yourself.
- pdonis 2y ago> That's typically _not_ what post-modernism is It's not what post-modernists typically say post-modernism is. But I'm not relying on what they say it is. I've read enough post-modernism to form my own opinion. > Read and think by yourself. I have. See above.
- 2OEH8eoCRo0 2y agoI'm not sure about every industry but it becomes especially tricky with software. I worked at a manufacturing plant and they put dashboards on monitors everywhere so the whole plant was always aware of their performance. This was easy to measure because they made physical goods! How do you measure output and performance in software?
- Juliate 2y agoThe root issue is the superior not having a clue. Sonar in this case, is sadly enabling this type of superior to be even more harmful, not to the developers only, but to the actual business of the company. And Sonar is far from being alone in this. JIRA is the most glaring example I can think of. Growing companies implement cargo-culted tools without understanding the needs and requirements, and let themselves drift into templates or "best practices" that are not relevant or beneficial to their own operations as-is, resulting in a sum of frustrations, whose impact on the work and the teams they acknowledge only way too late. The care you need to inject not only in your tools, but how they are apprehended by both your customers and their primary users (which may have very different, if not opposed, perspectives on how/why to use it), from pricing, to documentation, to use-cases... This is especially very complex when your tool answers to a regulation requirement, because it's very often received as a constraining/oppressing "solution", rather than an enabling one: it may be confortable to you as a seller, and confortable to your customer, but it may also be a counter-sale point to your (customer's) users that will impact future consideration when they become purchasing agents themselves.
- marcosdumay 2y agoYes... but how often have you experienced a non-clueless linter? Some tools bias people into doing bad things. It's not exactly the tools fault, and they may even have good uses (like Bash linters), but tools guide people and it's good to remind people not to follow.
- icholy 2y agoWe used to have a rule where you couldn't move issues "backwards" in the workflow. Accidentally closed an issue? Gotta create a new one.
- wetpaws 2y agoWe use sonar at work and this resonates so much with me.
- zamalek 2y agoI'm not sure how much value sonar adds where I work (dotnet). It enormously affects build times, and I've yet to experience a single true positive in 2 years (apart from the code coverage dashboard). The amount of MRR you can generate by vaguely being related to mitigating vulnerabilities is incredible.
- coredog64 2y agoI worked at a place that was full of junior contractors who had a large incentive to ship and no incentives for support. Sonar was good about finding bugs that they should have fixed but didn’t give a rip about (e.g. not closing database connections on all paths)
- philipwhiuk 2y agoSonarqube issues were the warning for the SOC-report powered issue scanners that have arrived more recently.
- Emigre_ 2y agoSonar doesn't seem to really work in my limited experience. It adds a lot of of time to builds, at least in the cases I've seen, while there are alternate linters or code quality tools capable of doing the same at a fraction of the time. Build times and development speed matter!... They matter a lot. You need a quick feedback loop.
- ars 2y agoI use Sonar all the time, but not during build. It runs live while I'm editing a file. I've not noticed any slowdown at all, and it's certainly a quick feedback loop (it runs when I save the file). I've found the majority of its suggestions helpful, and the ones that are not I simply ignore.
- nsxwolf 2y agoIt adds about 2 minutes to our gitlab pipelines but the major issue with it is when organizations decide failures should prevent merging code to master or even deploying to a QA environment. That's the real time sink - figuring out how to get past it. It's a lot more than 2 minutes, sometimes even days if it's something you can't work around and have to go through the red tape if your team isn't empowered to take charge of your own pipelines.
- raiyni 2y agoYou think 2 minutes is bad, try using fortify. Scans can easily be hours.
- Emigre_ 2y agoI should have mentioned that I was referring actually to the continuous integration pipeline, not actually to the build itself. Not very well explained on my side. I've never used it locally myself. I don't really know why the CI setups that were using Sonar I've seen in the past were that slow, to be honest.
- watwut 2y agoIsn't the actual issue here the superior managing the sonar being a controlling jerk? Turning off the rules on sonar is easy, technically. The issue is social.
- kriiuuu 2y agoYes. I would quickly look for a new job. A linter should help the programmer along the way, but be easy to disable when it’s invalid.
- elpocko 2y ago>SonarQube (formerly Sonar) is an open-source platform developed by SonarSource for continuous inspection of code quality to perform automatic reviews with static analysis of code to detect bugs and code smells on 29 programming languages. https://en.wikipedia.org/wiki/SonarQube https://en.wikipedia.org/wiki/SonarQube
- eigenvalue 2y agoThis sounds truly hellish, like being controlled by a stupid robot straight out of Kafka's "The Trial." They should allow special one off exception that are documented with a comment, similar to how you can disable Ruff warnings in python code for a single like # noqa: F401
- EricRiese 2y agoThey do // Nosonar
- thfuran 2y agoAnd @SuppressWarning for a specific rule id
- nsxwolf 2y agoGoogle "nosonar doesn't work" for a million war stories about how this is not a solution.
- jahlove 2y agoIn my organization's sonarqube configuration (where of course every flag is turned on), `// nosonar` actually shows up as a code smell
- jimbokun 2y ago> In my case, I have a superior who administers Sonar and is, let’s say, completely committed to it. For any ‘exception granted’ we would have to book time with them days in advance then white-board the reason why Sonar is wrong, or produce a sample program - who has got time for that with tight deadlines? This superior (sic) is what a negative productivity employee looks like.
- thiht 2y agoYes, this is an organization issue, not a Sonar issue. It might also be a communication issue if the team doesn't challenge the status quo, because this situation is terrible: > For any ‘exception granted’ we would have to book time with them days in advance then white-board the reason why Sonar is wrong (no evidence for that, maybe they did challenge it and the superior refused, but I just wanted to mention it)
- pacifika 2y agoAre the defaults emphatic to the engineer or to the ruleset?
- nsxwolf 2y agoWe frequently have the issue of, upon refactoring code in such a way that involves moving it and its tests to a new file, Sonar will take away our previous "credit" for code coverage percentage, dropping our project below the threshold and failing. The only workaround I've found is to create a new function, fill it full of many useless no-op lines, and write a test for that function, just to bump the percentages back up. This is often harder than it sounds, because the linter will block many types of useless no-op code. We then remove the code as part of another ticket.
- lesuorac 2y agoHeh, at one place I wrote some java code that would use reflections to test the getter/setters in a POJO so that it wouldn't end up with 0% code coverage.
- cuteboy19 2y agogetter setters w/o buisness logic seem like an antipattern though. let spring or some other annotation handle those
- lesuorac 2y agoEh, whats the difference between spring auto-generating them at build time via an annotation or an IDE auto-generating them at write time?
- cuteboy19 2y agocoverage is not affected
- hsbbxbyb 2y agoIDE auto generation is frozen in time. You have a bunch of useless boilerplate you still need to look at to make sure nobody did something unexpected in them When annotation generated or reflection based, you only have the really interesting ones in source code to care about
- karussell 2y agoadd (2023)?
- icholy 2y agoAt my work you can mark any issue with "won't fix". The issues are right pretty often though.
- dgan 2y agoSonar tries hard to have an authority of a compiler, while having the resources of a linter. I am not saying it's snake oil, but honestly how i ve seen ut being used, it's not that far
- move-on-by 2y agoI sympathize with the OP. Having said that, I’ve rolled out SonarCloud to two different companies and I would not hesitate to roll it out to a third if given the opportunity. Initially, people always come out of the woodwork insisting that the gate requirements must be hard blockers and that we can just hand wave away the issues OP listed by tweaking the project rules. I always fight them, insisting that teams should be the owners and to gain quick adoption it should just be considered as another tool for PR reviewers. Eventually, people back off and come to accept that Sonar can be really helpful, but at the end of the day the developers should be trusted to make the right call for the situation. It’s not like we aren’t still requiring code reviews. I feel for OP, but it’s not Sonar’s fault the tool is being used for evil instead of good. This last time I implemented SonarCloud, I took an anonymous survey to get peoples opinion. For the most part people liked the feedback Sonar provided. More junior engineers and more senior engineers liked it the most- midlevel engineers not so much. The junior liked getting quick feedback prior to asking for code reviews. The more senior engineers - who spend a lot of their time doing PR reviews - liked that it handled more of the generic stuff so that they could focus more on the business logic or other aspects of the PR. It’s just another tool in the toolbox.
- cuteboy19 2y agotheir point is that a hammer shaped tool will be used to hammer. its more about what the tool defaults to doing that is the problem
- salawat 2y agoThere is no anonymous survey with the metadata available to an organization as a matter of routine. Between your OPS people, and just local onowledge, unmasking can be a trivial affair.
- sigotirandolas 2y agoI saw a case where Sonar analysis was being requested by a government agency where software was built by consultants. From the government agency's point of view it made some sense to ensure that the code delivered by the consultants wasn't full-on spaghetti. However, I saw it causing similar turd polishing behaviour: Sensible code needing to be changed because it exceeded some obstinate metric, any kind of code movement causing existing issues to appear as "new", false positives due to incomplete language feature support, etc.
- ch_123 2y agoAny sort of static analysis/linting tools will occasionally make bad/unhelpful/stupid suggestions, some moreso than others. At any place where I've had to use such tools, I've always had the ability to either tweak the settings, or have a conversation with the people who decide them and make appropriate changes. In this case, it sounds like bad culture and/or bad colleagues are driving this person to despair, and not Sonar as per se.
- gewenyu99 2y agoWell, we built Trunk Check to address some of these issues. Maybe it'll suit your org better. - We support hold-the-line: we only lint on diffs so you can refactor as you go. Gradual adoption. - Use existing configs: use standard OSS tools you know. Trunk Check runs them with standardized rules and output format. - Better config management: define config within each repo and still let you do shared configs across the org by defining your own plugin repos. - Better ignores: You can define line and project level ignores in the repo - Still have nightly reporting: We do let you run nightly on all changes and report them to track code base health and catch high-risk vulnerabilities and issues. There's a web app to view everything. Try it and let me know how it goes. https://docs.trunk.io/check/usage https://docs.trunk.io/check/usage