Very slow scanning process at large and legacy java project

Viewed 652

Hi i´m working with a big and legacy product, and i have some performance issues when i run my sonar scanner.

Product:

  • More than 600k loc
  • More than 8k vulnerabilities
  • 2k bugs
  • 100k code smells
  • More than 4k classes
  • Duplication 12%
  • A lot of cyclomatic complexity and cognitive issues

I know that are some Rules that causes more slow than others. But i don´t know how to find out which are these slowest rules.

Relevant properties:

  • Java source and target version is 1.6
  • Maven wrapper 3.6.1
  • Maven compiler plugin 3.6.0
  • Maven surefire plugin 2.22.2
  • Sonar maven plugin 3.6.1.1688
  • Sonar server is 6.7

Some of my properties:

<sonar.language>java</sonar.language>
<sonar.java.source>1.6</sonar.java.source>

Analysis report generated dir size=107 MB

Slowest steps:

Java Main Files AST scan
Sensor JavaSquidSensor
sh “export MAVEN_OPTS=’-Xms1512m -Xmx8096m -XX:PermSize=512m -XX:MaxPermSize=1024m -XX:ReservedCodeCacheSize=128m’ ;” +" ./mvnw sonar:sonar -T 4 -X"

It tooks 09:30 hours to run sonar. 00:30 is about sending the scanner results to server and 9 hours is about running the scanner.

0 Answers
Related