From a323b5bc3e8a774ec5edc566b58e249602ea4af3 Mon Sep 17 00:00:00 2001 From: marcello33 Date: Wed, 11 Jan 2023 17:33:53 +0100 Subject: [PATCH] sonarqube integration (#658) * dev: add: sonarqube integration into security-ci * dev: add: exclude java files from sonarqube analysis --- .github/workflows/security-ci.yml | 28 +++++++++++++++++++++++++++- sonar-project.properties | 2 ++ 2 files changed, 29 insertions(+), 1 deletion(-) create mode 100644 sonar-project.properties diff --git a/.github/workflows/security-ci.yml b/.github/workflows/security-ci.yml index 5dc2b221db..c85675a30b 100644 --- a/.github/workflows/security-ci.yml +++ b/.github/workflows/security-ci.yml @@ -1,5 +1,5 @@ name: Security CI -on: [push, pull_request] +on: [ push, pull_request ] jobs: snyk: @@ -62,3 +62,29 @@ jobs: with: name: raw-report path: raw-report.json + + sonarqube: + name: SonarQube + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + with: + # Disabling shallow clone is recommended for improving relevancy of reporting. + fetch-depth: 0 + + # Triggering SonarQube analysis as results of it are required by Quality Gate check. + - name: SonarQube Scan + uses: sonarsource/sonarqube-scan-action@master + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} + + # Check the Quality Gate status. + - name: SonarQube Quality Gate check + id: sonarqube-quality-gate-check + uses: sonarsource/sonarqube-quality-gate-action@master + # Force to fail step after specific time. + timeout-minutes: 5 + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }} diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 0000000000..7ef7cb5ca4 --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,2 @@ +sonar.projectKey=maticnetwork_bor_AYWWvIEKoHLw1uOg0ppA +sonar.exclusions=crypto/secp256k1/libsecp256k1/src/java/org/bitcoin/*.java