From 91cf7daed5971619a0952007b50ba2b1d9053ece Mon Sep 17 00:00:00 2001 From: Nimit Date: Tue, 20 Jun 2023 11:32:56 +0000 Subject: [PATCH 1/2] added sonar properties to repo Signed-off-by: Nimit --- sonar-project.properties | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 sonar-project.properties diff --git a/sonar-project.properties b/sonar-project.properties new file mode 100644 index 0000000000..42c4949ff0 --- /dev/null +++ b/sonar-project.properties @@ -0,0 +1,8 @@ +sonar.projectKey=habitat-sh_habitat_AYi0h-B8ub6NcyE4pK8b + +# project name defaults to project key +sonar.projectName=Chef-Habitat-habitat + +# Path is relative to the sonar-project.properties file. Replace "\" by "/" on Windows. +sonar.sources= +sonar.exclusions= From 8517b9b7568e5b5e70b49397706e5a94ee5bc719 Mon Sep 17 00:00:00 2001 From: Nimit Date: Tue, 20 Jun 2023 11:35:46 +0000 Subject: [PATCH 2/2] added sonarqube.yml for github workflow Signed-off-by: Nimit --- .github/workflows/sonarqube.yml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/workflows/sonarqube.yml diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml new file mode 100644 index 0000000000..2b8136f43e --- /dev/null +++ b/.github/workflows/sonarqube.yml @@ -0,0 +1,25 @@ +name: SonarQube scan + +on: + # Trigger analysis when pushing to your main branches, and when creating a pull request. + push: + branches: + - main + - develop + - 'release/**' + pull_request: + types: [opened, synchronize, reopened] + +jobs: + sonarqube: + runs-on: ip-range-controlled + steps: + - uses: actions/checkout@v3 + with: + # Disabling shallow clone is recommended for improving relevancy of reporting + fetch-depth: 0 + - name: SonarQube Scan + uses: sonarsource/sonarqube-scan-action@master + env: + SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} + SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}