Skip to content

SonarCloud PR Scan

SonarCloud PR Scan #24

# Copyright (c) 2026 Elektrobit Automotive GmbH
#
# This program and the accompanying materials are made available under the
# terms of the Apache License, Version 2.0 which is available at
# https://www.apache.org/licenses/LICENSE-2.0.
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
#
# SPDX-License-Identifier: Apache-2.0
# Runs the actual SonarCloud upload for pull requests. Split out from
# sonarcloud.yml because fork PRs never receive SONAR_TOKEN. workflow_run runs
# in the trusted base branch context and only downloads already-built reports
# - it never builds or executes PR code.
name: SonarCloud PR Scan
on:
workflow_run:
workflows: ["SonarCloud Analysis"]
types: [completed]
permissions:
actions: read
contents: read
concurrency:
group: "sonarcloud-pr-scan-${{ github.event.workflow_run.id }}"
cancel-in-progress: true
jobs:
scan:
name: SonarCloud Scan
runs-on: ubuntu-latest
if: github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.conclusion == 'success'
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 0
- name: Download analysis reports
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: sonar-reports
path: reports
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Read PR metadata
id: pr
run: |
{
echo "number=$(jq -r .number reports/pr.json)"
echo "head_sha=$(jq -r .headSha reports/pr.json)"
echo "head_ref=$(jq -r .headRef reports/pr.json)"
echo "base_ref=$(jq -r .baseRef reports/pr.json)"
} >> "$GITHUB_OUTPUT"
- name: SonarCloud Scan
uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
with:
args: >
-Dsonar.pullrequest.key=${{ steps.pr.outputs.number }}
-Dsonar.pullrequest.branch=${{ steps.pr.outputs.head_ref }}
-Dsonar.pullrequest.base=${{ steps.pr.outputs.base_ref }}
-Dsonar.pullrequest.provider=github
-Dsonar.pullrequest.github.repository=${{ github.repository }}
-Dsonar.scm.revision=${{ steps.pr.outputs.head_sha }}
-Dsonar.qualitygate.wait=true