Skip to content

SonarQube

SonarQube #8

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# SonarQube Cloud (SonarCloud) static analysis. Analysis scope + exclusions live
# in sonar-project.properties. Requires the SONAR_TOKEN repository secret
# (Settings -> Secrets and variables -> Actions) and a SonarCloud project:
# https://sonarcloud.io/project/overview?id=hyperpolymath_dicta-task
# Mirrors the boj-server arrangement.
#
# WHY THE TOKEN GUARD (added 2026-07-28)
# --------------------------------------
# This repo has NO Actions secrets configured at all, so `secrets.SONAR_TOKEN`
# expanded to the empty string and the scanner failed every run with
# "Not authorized or project not found" -- a permanent red that blocked merges
# through the ruleset's code_quality rule. It was never a code-quality signal:
# the scan never ran.
#
# SonarCloud's AUTOMATIC analysis is separately enabled here and does report
# (check name "SonarCloud Code Analysis"), so no coverage is lost by skipping.
#
# The guard makes the state honest rather than red: with no token the job
# reports that it is unconfigured and exits 0; the moment a SONAR_TOKEN secret
# is added it runs for real, with no further edit needed. Deleting the workflow
# would have discarded a correct configuration over a missing secret.
name: SonarQube
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
sonarqube:
name: SonarQube
runs-on: ubuntu-latest
timeout-minutes: 15
# Secrets cannot be referenced from a job-level `if:`, so the presence test
# is carried through an env var set at job scope and read in a first step.
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
steps:
- name: Report configuration state
id: cfg
run: |
if [ -z "${SONAR_TOKEN}" ]; then
echo "configured=false" >> "$GITHUB_OUTPUT"
echo "::notice::SONAR_TOKEN is not configured for this repository - skipping the CI-based scan."
echo "SonarCloud automatic analysis (check: 'SonarCloud Code Analysis') is unaffected."
echo "To enable this scan: Settings > Secrets and variables > Actions > new secret SONAR_TOKEN."
else
echo "configured=true" >> "$GITHUB_OUTPUT"
echo "SONAR_TOKEN present - running the CI-based scan."
fi
- name: Checkout
if: steps.cfg.outputs.configured == 'true'
uses: actions/checkout@v7.0.1
with:
fetch-depth: 0 # full history for accurate new-code detection
- name: SonarQube Scan
if: steps.cfg.outputs.configured == 'true'
uses: SonarSource/sonarqube-scan-action@v8.3.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}