From 9e770aa8c8d27ef36d895a34ba5fac6af4993fbf Mon Sep 17 00:00:00 2001 From: ssvoss Date: Mon, 5 Oct 2026 14:37:08 -0400 Subject: [PATCH] Add Sonar coverage artifact support --- .../workflows/CHANGELOGS/run_sonar_scan.md | 6 +++ .github/workflows/READMES/run_sonar_scan.md | 47 +++++++++++++++++-- .github/workflows/run_sonar_scan.yml | 17 +++++++ 3 files changed, 65 insertions(+), 5 deletions(-) diff --git a/.github/workflows/CHANGELOGS/run_sonar_scan.md b/.github/workflows/CHANGELOGS/run_sonar_scan.md index 75de097..0af1c9e 100644 --- a/.github/workflows/CHANGELOGS/run_sonar_scan.md +++ b/.github/workflows/CHANGELOGS/run_sonar_scan.md @@ -2,6 +2,12 @@ All notable changes to the **run_sonar_scan** callable workflow are documented in this file. +## 1.3.0 + +### Added + +- Added optional `coverage-artifact-name` and `coverage-artifact-path` inputs to download a same-run coverage artifact before the SonarQube scan. + ## 1.2.0 ### Changed diff --git a/.github/workflows/READMES/run_sonar_scan.md b/.github/workflows/READMES/run_sonar_scan.md index b3acdf1..775c927 100644 --- a/.github/workflows/READMES/run_sonar_scan.md +++ b/.github/workflows/READMES/run_sonar_scan.md @@ -1,6 +1,6 @@ # Run SonarQube Scan -This reusable workflow checks out the ref that triggered the caller, or a specified commit or ref, and runs a SonarQube scan with full Git history. +This reusable workflow checks out the ref that triggered the caller, or a specified commit or ref, and runs a SonarQube scan with full Git history. Callers can optionally download a coverage artifact produced earlier in the same workflow run before the scan starts. ## Prerequisites @@ -11,7 +11,7 @@ The consuming repository must include its SonarQube configuration, such as a `so ```yaml jobs: sonar-scan: - uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.2.0 + uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.3.0 secrets: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} ``` @@ -23,11 +23,48 @@ with: commit-identifier: ${{ github.sha }} ``` +To import coverage produced by another job, upload the report as an artifact and make the Sonar job depend on the test job: + +```yaml +jobs: + unit-tests: + runs-on: ubuntu-26.04 + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + + - name: Install dependencies + run: npm ci + + - name: Run tests with coverage + run: npm test -- --coverage + + - name: Upload coverage + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: unit-test-coverage + path: coverage/lcov.info + if-no-files-found: error + + sonar-scan: + needs: unit-tests + uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@ + with: + coverage-artifact-name: unit-test-coverage + coverage-artifact-path: .coverage + secrets: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} +``` + +This downloads the report to `.coverage/lcov.info`. Configure SonarQube to read that location, for example with `sonar.javascript.lcov.reportPaths=.coverage/lcov.info`. The workflow does not run tests or generate coverage. If `coverage-artifact-name` is set but the artifact does not exist, the download step fails the job. + ## Inputs -| Input | Type | Required | Default | Description | -| ------------------- | ------ | -------- | --------------------- | ------------------------------------------------- | -| `commit-identifier` | string | No | Triggering ref or SHA | Commit SHA, tag, or branch to check out and scan. | +| Input | Type | Required | Default | Description | +| ------------------------ | ------ | -------- | --------------------- | --------------------------------------------------------------------------- | +| `commit-identifier` | string | No | Triggering ref or SHA | Commit SHA, tag, or branch to check out and scan. | +| `coverage-artifact-name` | string | No | `''` | Name of a coverage artifact uploaded earlier in the same workflow run. | +| `coverage-artifact-path` | string | No | `.` | Directory into which the coverage artifact is downloaded before the scan. | ## Secrets diff --git a/.github/workflows/run_sonar_scan.yml b/.github/workflows/run_sonar_scan.yml index e9183b5..d40dfe1 100644 --- a/.github/workflows/run_sonar_scan.yml +++ b/.github/workflows/run_sonar_scan.yml @@ -8,6 +8,16 @@ on: type: string required: false default: '' + coverage-artifact-name: + description: Name of a coverage artifact uploaded earlier in the same workflow run + type: string + required: false + default: '' + coverage-artifact-path: + description: Directory into which the coverage artifact is downloaded + type: string + required: false + default: '.' secrets: SONAR_TOKEN: required: true @@ -27,6 +37,13 @@ jobs: ref: ${{ inputs.commit-identifier }} fetch-depth: 0 + - name: Download coverage artifact + if: ${{ inputs.coverage-artifact-name != '' }} + uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0 + with: + name: ${{ inputs.coverage-artifact-name }} + path: ${{ inputs.coverage-artifact-path }} + - name: Run SonarQube scan uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 env: