mirror of
https://github.com/ethereum/go-ethereum.git
synced 2026-07-25 06:06:44 +00:00
sonarqube integration (#658)
* dev: add: sonarqube integration into security-ci * dev: add: exclude java files from sonarqube analysis
This commit is contained in:
parent
5ae1b16970
commit
a323b5bc3e
2 changed files with 29 additions and 1 deletions
28
.github/workflows/security-ci.yml
vendored
28
.github/workflows/security-ci.yml
vendored
|
|
@ -1,5 +1,5 @@
|
|||
name: Security CI
|
||||
on: [push, pull_request]
|
||||
on: [ push, pull_request ]
|
||||
|
||||
jobs:
|
||||
snyk:
|
||||
|
|
@ -62,3 +62,29 @@ jobs:
|
|||
with:
|
||||
name: raw-report
|
||||
path: raw-report.json
|
||||
|
||||
sonarqube:
|
||||
name: SonarQube
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
with:
|
||||
# Disabling shallow clone is recommended for improving relevancy of reporting.
|
||||
fetch-depth: 0
|
||||
|
||||
# Triggering SonarQube analysis as results of it are required by Quality Gate check.
|
||||
- name: SonarQube Scan
|
||||
uses: sonarsource/sonarqube-scan-action@master
|
||||
env:
|
||||
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
|
||||
SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
|
||||
|
||||
# Check the Quality Gate status.
|
||||
- name: SonarQube Quality Gate check
|
||||
id: sonarqube-quality-gate-check
|
||||
uses: sonarsource/sonarqube-quality-gate-action@master
|
||||
# Force to fail step after specific time.
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
|
||||
SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
|
||||
|
|
|
|||
2
sonar-project.properties
Normal file
2
sonar-project.properties
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
sonar.projectKey=maticnetwork_bor_AYWWvIEKoHLw1uOg0ppA
|
||||
sonar.exclusions=crypto/secp256k1/libsecp256k1/src/java/org/bitcoin/*.java
|
||||
Loading…
Reference in a new issue