SonarQube #8
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # SonarQube Cloud (SonarCloud) static analysis. Analysis scope + exclusions live | |
| # in sonar-project.properties. Requires the SONAR_TOKEN repository secret | |
| # (Settings -> Secrets and variables -> Actions) and a SonarCloud project: | |
| # https://sonarcloud.io/project/overview?id=hyperpolymath_dicta-task | |
| # Mirrors the boj-server arrangement. | |
| # | |
| # WHY THE TOKEN GUARD (added 2026-07-28) | |
| # -------------------------------------- | |
| # This repo has NO Actions secrets configured at all, so `secrets.SONAR_TOKEN` | |
| # expanded to the empty string and the scanner failed every run with | |
| # "Not authorized or project not found" -- a permanent red that blocked merges | |
| # through the ruleset's code_quality rule. It was never a code-quality signal: | |
| # the scan never ran. | |
| # | |
| # SonarCloud's AUTOMATIC analysis is separately enabled here and does report | |
| # (check name "SonarCloud Code Analysis"), so no coverage is lost by skipping. | |
| # | |
| # The guard makes the state honest rather than red: with no token the job | |
| # reports that it is unconfigured and exits 0; the moment a SONAR_TOKEN secret | |
| # is added it runs for real, with no further edit needed. Deleting the workflow | |
| # would have discarded a correct configuration over a missing secret. | |
| name: SonarQube | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: [main, master] | |
| workflow_dispatch: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| sonarqube: | |
| name: SonarQube | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| # Secrets cannot be referenced from a job-level `if:`, so the presence test | |
| # is carried through an env var set at job scope and read in a first step. | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} | |
| steps: | |
| - name: Report configuration state | |
| id: cfg | |
| run: | | |
| if [ -z "${SONAR_TOKEN}" ]; then | |
| echo "configured=false" >> "$GITHUB_OUTPUT" | |
| echo "::notice::SONAR_TOKEN is not configured for this repository - skipping the CI-based scan." | |
| echo "SonarCloud automatic analysis (check: 'SonarCloud Code Analysis') is unaffected." | |
| echo "To enable this scan: Settings > Secrets and variables > Actions > new secret SONAR_TOKEN." | |
| else | |
| echo "configured=true" >> "$GITHUB_OUTPUT" | |
| echo "SONAR_TOKEN present - running the CI-based scan." | |
| fi | |
| - name: Checkout | |
| if: steps.cfg.outputs.configured == 'true' | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| fetch-depth: 0 # full history for accurate new-code detection | |
| - name: SonarQube Scan | |
| if: steps.cfg.outputs.configured == 'true' | |
| uses: SonarSource/sonarqube-scan-action@v8.3.0 | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} |