Repository navigation
82 lines (70 loc) · 2.71 KB
/
Copy pathsonarcloud.yml
File metadata and controls
82 lines (70 loc) · 2.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# Copyright (c) 2026 Elektrobit Automotive GmbH
#
# This program and the accompanying materials are made available under the
# terms of the Apache License, Version 2.0 which is available at
# https://www.apache.org/licenses/LICENSE-2.0.
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
#
# SPDX-License-Identifier: Apache-2.0
name: SonarCloud Analysis
on:
pull_request:
push:
branches:
- main
- release-**
concurrency:
group: "sonarcloud-${{ github.head_ref || github.ref }}"
cancel-in-progress: true
jobs:
sonarcloud:
name: SonarCloud Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: ./.github/actions/ci-setup
- name: Run unit tests
run: python3 run_checks.py --utest
- name: Run coverage
run: python3 run_checks.py --cov
- name: Run lint
run: python3 run_checks.py --lint
- name: Run pep8 codestyle check
run: python3 run_checks.py --pep8
# Secrets are withheld from pull_request runs opened by Dependabot or from forks,
# so the scan itself can't happen here. Persist the reports + PR metadata as an
# artifact and let the trusted sonarcloud-pr-scan.yml (workflow_run) do the upload.
- name: Save PR metadata
if: github.event_name == 'pull_request'
env:
PR_NUMBER: ${{ github.event.pull_request.number }}
PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }}
PR_HEAD_REF: ${{ github.event.pull_request.head.ref }}
PR_BASE_REF: ${{ github.event.pull_request.base.ref }}
run: |
jq -n \
--arg number "$PR_NUMBER" \
--arg headSha "$PR_HEAD_SHA" \
--arg headRef "$PR_HEAD_REF" \
--arg baseRef "$PR_BASE_REF" \
'{number: $number, headSha: $headSha, headRef: $headRef, baseRef: $baseRef}' \
> reports/pr.json
- name: Upload analysis reports
if: github.event_name == 'pull_request'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sonar-reports
path: reports
retention-days: 1
- name: SonarCloud Scan
if: github.event_name == 'push'
uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}