| # Licensed to the Apache Software Foundation (ASF) under one or more |
| # contributor license agreements. See the NOTICE file distributed with |
| # this work for additional information regarding copyright ownership. |
| # The ASF licenses this file to You under the Apache License, Version 2.0 |
| # (the "License"); you may not use this file except in compliance with |
| # the License. You may obtain a copy of the License at |
| # |
| # http://www.apache.org/licenses/LICENSE-2.0 |
| # |
| # Unless required by applicable law or agreed to in writing, software |
| # distributed under the License is distributed on an "AS IS" BASIS, |
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| # See the License for the specific language governing permissions and |
| # limitations under the License. |
| # |
| # Supply-chain pinning policy: every third-party Action below is pinned to a full commit SHA, |
| # not a floating tag, because a tag is mutable and a SHA pin is what makes "what code ran in CI" |
| # part of this project's provenance story. To bump: resolve the new tag to its full commit SHA |
| # and update the trailing "# vX.Y.Z" comment to match. Same policy applies to maven.yml and |
| # codeql-analysis.yml. |
| name: SonarQube |
| |
| on: |
| push: |
| branches: |
| - master |
| pull_request: |
| types: [opened, synchronize, reopened] |
| |
| permissions: |
| contents: read |
| pull-requests: read |
| |
| jobs: |
| build: |
| name: Build and analyze |
| runs-on: ubuntu-latest |
| env: |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} |
| steps: |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| with: |
| fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis |
| persist-credentials: false |
| - name: Set up JDK 17 |
| uses: actions/setup-java@dd06d9cba3e5552c54d9f8ea23572deb30010f7c # v6.0.0 |
| with: |
| java-version: 17 |
| distribution: 'temurin' # Alternative distribution options are available. |
| - name: Cache SonarQube packages |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6 |
| with: |
| path: ~/.sonar/cache |
| key: ${{ runner.os }}-sonar |
| restore-keys: ${{ runner.os }}-sonar |
| - name: Cache Maven packages |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6 |
| with: |
| path: ~/.m2 |
| key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} |
| restore-keys: ${{ runner.os }}-m2 |
| # When SONAR_TOKEN is unset (e.g. pull_request from a fork, or secret not configured), |
| # SonarCloud returns "Project not found". Run Maven verify always; scan only if token exists. |
| - name: Build (tests and coverage) |
| env: |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information, if any |
| run: mvn -B clean verify |
| |
| - name: SonarCloud analysis |
| if: ${{ env.SONAR_TOKEN != '' }} |
| env: |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
| run: | |
| mvn -B org.sonarsource.scanner.maven:sonar-maven-plugin:sonar \ |
| -Dsonar.projectKey=apache_juneau \ |
| -Dsonar.organization=apache \ |
| -Dsonar.host.url=https://sonarcloud.io \ |
| -Dsonar.login=$SONAR_TOKEN |