When HTTPS_PROXY or https_proxy is set, download the public key over HTTPS,
validate that exactly one primary key matches the requested fingerprint, and
import it from memory. Retry retrieval using the fallback keyserver when the
primary attempt fails.
Keep native GPG key retrieval when no HTTPS proxy is configured and update
the tests and generated distribution files.
Signed-off-by: Torbjörn SVENSSON <torbjorn.svensson@foss.st.com>
Emit a warning when SONARCLOUD_URL is set, directing users to either
pass nothing, use SONAR_REGION=us for the US region, or pass
-Dsonar.scanner.sonarcloudUrl and -Dsonar.scanner.apiBaseUrl via args
for advanced needs. Backward compatibility is preserved.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Organisations using private Artifactory mirrors require authentication to
download the SonarScanner CLI. This adds an optional scannerBinariesAuthHeader
input whose value is forwarded as the Authorization HTTP header to both the
binary and GPG signature downloads via tc.downloadTool's built-in auth
parameter. No new dependencies are introduced.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>