Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/run_sonar_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **run_sonar_scan** callable workflow are documented in this file.

## 1.3.0

### Added

- Added optional `coverage-artifact-name` and `coverage-artifact-path` inputs to download a same-run coverage artifact before the SonarQube scan.

## 1.2.0

### Changed
Expand Down
47 changes: 42 additions & 5 deletions .github/workflows/READMES/run_sonar_scan.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Run SonarQube Scan

This reusable workflow checks out the ref that triggered the caller, or a specified commit or ref, and runs a SonarQube scan with full Git history.
This reusable workflow checks out the ref that triggered the caller, or a specified commit or ref, and runs a SonarQube scan with full Git history. Callers can optionally download a coverage artifact produced earlier in the same workflow run before the scan starts.

## Prerequisites

Expand All @@ -11,7 +11,7 @@ The consuming repository must include its SonarQube configuration, such as a `so
```yaml
jobs:
sonar-scan:
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.2.0
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.3.0
secrets:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
```
Expand All @@ -23,11 +23,48 @@ with:
commit-identifier: ${{ github.sha }}
```

To import coverage produced by another job, upload the report as an artifact and make the Sonar job depend on the test job:

```yaml
jobs:
unit-tests:
runs-on: ubuntu-26.04
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install dependencies
run: npm ci

- name: Run tests with coverage
run: npm test -- --coverage

- name: Upload coverage
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: unit-test-coverage
path: coverage/lcov.info
if-no-files-found: error

sonar-scan:
needs: unit-tests
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@<released-sha>
with:
coverage-artifact-name: unit-test-coverage
coverage-artifact-path: .coverage
secrets:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
```

This downloads the report to `.coverage/lcov.info`. Configure SonarQube to read that location, for example with `sonar.javascript.lcov.reportPaths=.coverage/lcov.info`. The workflow does not run tests or generate coverage. If `coverage-artifact-name` is set but the artifact does not exist, the download step fails the job.

## Inputs

| Input | Type | Required | Default | Description |
| ------------------- | ------ | -------- | --------------------- | ------------------------------------------------- |
| `commit-identifier` | string | No | Triggering ref or SHA | Commit SHA, tag, or branch to check out and scan. |
| Input | Type | Required | Default | Description |
| ------------------------ | ------ | -------- | --------------------- | --------------------------------------------------------------------------- |
| `commit-identifier` | string | No | Triggering ref or SHA | Commit SHA, tag, or branch to check out and scan. |
| `coverage-artifact-name` | string | No | `''` | Name of a coverage artifact uploaded earlier in the same workflow run. |
| `coverage-artifact-path` | string | No | `.` | Directory into which the coverage artifact is downloaded before the scan. |

## Secrets

Expand Down
17 changes: 17 additions & 0 deletions .github/workflows/run_sonar_scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,16 @@ on:
type: string
required: false
default: ''
coverage-artifact-name:
description: Name of a coverage artifact uploaded earlier in the same workflow run
type: string
required: false
default: ''
coverage-artifact-path:
description: Directory into which the coverage artifact is downloaded
type: string
required: false
default: '.'
secrets:
SONAR_TOKEN:
required: true
Expand All @@ -27,6 +37,13 @@ jobs:
ref: ${{ inputs.commit-identifier }}
fetch-depth: 0

- name: Download coverage artifact
if: ${{ inputs.coverage-artifact-name != '' }}
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
with:
name: ${{ inputs.coverage-artifact-name }}
path: ${{ inputs.coverage-artifact-path }}

- name: Run SonarQube scan
uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0
env:
Expand Down
Loading