pr decoration failed: could not find pull request for commit
Fixes SonarQube's 'pr decoration failed: could not find pull request for commit' error. Use it when SonarQube analyzes a PR branch but cannot link the analysis to the pull request. Key trigger: the analysis runs in CI on a PR but shows up as a plain branch, or PR decoration never appears.
TL;DR
Make sure the CI checkout fetches full git history and the scanner runs with PR context (the PR key, source branch, and base branch). SonarQube matches the analyzed commit to a pull request through the provider API; a shallow clone or missing PR parameters breaks the match and the analysis lands as a branch instead.
The error
pr decoration failed: could not find pull request for commitSteps to fix
- Check the checkout step: configure it to fetch full history (fetch-depth 0 in the checkout action) so the scanner can see the merge base and the PR refs.
- Expected: the clone includes full history, not a single shallow commit.
- Confirm the scanner gets PR context: when using the official SonarQube scan action inside a pull_request workflow it auto-detects; for manual scanner invocations, pass the PR key, source branch, and base branch parameters explicitly.
- Expected: the scanner log shows it detected a pull request context.
- Verify the analyzed commit is the PR head - if CI checked out a merge commit or an outdated SHA, push the PR branch again and re-run.
- Expected: the commit SHA in the SonarQube background task matches the PR head SHA.
- Re-run analysis.
- Expected: the project page shows the pull request (not a branch) and decoration - comments and checks - appears on the PR.
Use this when
- SonarQube logs "could not find pull request for commit" during PR analysis.
- PR analysis shows up under Branches instead of Pull Requests in SonarQube.
- Decoration (PR comments, status checks) is missing after a seemingly fine scan.
Not for this skill when
- The scan itself fails (fix the analysis error first).
- Decoration fails with an auth error rather than a missing-PR error (check the provider token).
- You're analyzing a plain branch on purpose (decoration only applies to PRs).
Variant phrasings
- sonarqube could not find pull request for commit
- pr decoration failed sonarqube github
- sonarqube pull request not detected in CI
- sonarqube analysis shows as branch instead of PR
Why it happens
PR decoration needs a 1:1 link between the analyzed commit and a pull request object in the git provider. The scanner finds that link from the local git topology (which PR ref contains this commit) plus the PR parameters. A shallow clone hides the topology, and without PR parameters the scanner files the analysis under the branch name - then decoration has no PR to attach to.
Edge cases
- PRs from forks: the scanner needs a token with pull-request read access on the base repo, or the provider lookup fails.
- Renamed default branch (main vs master): a stale base-branch parameter points the match at a branch that doesn't exist.
- Two CI jobs analyzing the same PR with different keys create duplicate PR entries - keep one scan per PR.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_WrSUcvrhUYVrazkfr2xepw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.