Skip to content

Follow-up quality gate #41-#49 - #52

Merged
AriusII merged 1 commit into
mainfrom
fix/client-sonar-quality-gate
Sep 21, 2026
Merged

AriusII merged 1 commit into
mainfrom
fix/client-sonar-quality-gate

Conversation

@AriusII

@AriusII AriusII commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Restores real Microsoft Testing Platform coverage for all seven *.Tests.csproj projects, using the officially supported Cobertura output.
  • Passes only the seven final reports to sonar.cs.cobertura.reportsPaths; collector staging copies are deliberately excluded to prevent duplicate coverage import.
  • Fails before sonarscanner end when a final report is missing, empty, malformed, or not Cobertura.
  • Makes the quality gate non-optional: sonar.qualitygate.wait=true with a 300-second timeout. A red or unavailable quality-gate result now fails the workflow.
  • Requires SONAR_TOKEN for an authorized analysis instead of emitting a successful skip, and fails closed if the analysis-method check cannot be verified.
  • Keeps the least-privilege workflow permissions and pull_request trigger; forks and Dependabot PRs are excluded before any repository secret is forwarded. Dependabot is identified from the PR author rather than the rerun actor.

Why

PRs #41 through #49 all completed with the Sonar job skipped because the repository variable SONAR_CI_ENABLED is absent, while the repository secret named SONAR_TOKEN is present. The reusable workflow also defaulted the quality-gate wait to false and no longer collected or imported coverage. This restores the coverage behavior introduced by 019814a while correcting its scanner/report handling and making the gate enforceable.

Validation

  • dotnet restore CheatEngine.Client.slnx --locked-mode
  • dotnet build CheatEngine.Client.slnx --configuration Release --no-restore --no-incremental --disable-build-servers --warnaserror
  • All seven MTP test projects passed: 553 passed, 0 failed, 0 skipped.
  • The workflow-equivalent test loop generated and validated seven final Cobertura XML reports.
  • actionlint 1.7.12 passed after SHA-256 verification.
  • git diff --check passed.

Activation after merge — intentionally not performed by this PR

Enable the guarded Sonar callers only when ready:

gh variable set SONAR_CI_ENABLED --repo CheatEngineNet/CheatEngine.Client --body true

This PR does not alter SONAR_TOKEN or the feature variable. After enabling it, verify a same-repository PR and a main push; consider requiring the resulting Sonar / Analyze check alongside CI / Gate in the main-branch ruleset.

Summary by CodeRabbit

  • CI Improvements
    • Sonar analysis now requires a configured access token and fails promptly when required setup or analysis steps encounter errors.
    • Quality-gate checks run automatically with an extended timeout.
    • Pull requests from automated dependency-update tools are excluded from Sonar analysis.
    • Test coverage is collected across all test projects, validated, and uploaded as a build artifact.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: bb26690b-7815-4cf9-aae8-5408d30338ba

📥 Commits

Reviewing files that changed from the base of the PR and between 02077c0 and bacec09.

📒 Files selected for processing (11)
  • .github/workflows/pull-request-ci.yml
  • .github/workflows/sonar.yml
  • Directory.Packages.props
  • eng/Tests.props
  • tests/CheatEngine.Client.Abstractions.Tests/packages.lock.json
  • tests/CheatEngine.Client.Core.Tests/packages.lock.json
  • tests/CheatEngine.Client.Extensions.DependencyInjection.Tests/packages.lock.json
  • tests/CheatEngine.Client.Fluent.Tests/packages.lock.json
  • tests/CheatEngine.Client.Hosting.Tests/packages.lock.json
  • tests/CheatEngine.Client.SourceGenerators.Lua.Tests/packages.lock.json
  • tests/CheatEngine.Client.Tests/packages.lock.json

Limit details: You’ve used all 10 included reviews currently available.


📝 Walkthrough

Walkthrough

The pull request updates Sonar workflow eligibility and enforcement. It adds mandatory token validation, unconditional analysis steps, Cobertura coverage generation and validation, report artifact upload, and centralized coverage package references for test projects.

Changes

Sonar CI workflow

Layer / File(s) Summary
Sonar workflow enforcement
.github/workflows/pull-request-ci.yml, .github/workflows/sonar.yml
Sonar eligibility uses the pull request author login. The Sonar workflow requires SONAR_TOKEN, validates analysis setup, runs setup and build steps unconditionally, and always waits for the quality gate.
Test coverage pipeline
.github/workflows/sonar.yml
The workflow runs all test projects with Microsoft Testing Platform Cobertura coverage. It validates each report and uploads the reports for non-cancelled runs.
Coverage package wiring
Directory.Packages.props, eng/Tests.props, tests/*/packages.lock.json
Test projects reference Microsoft.Testing.Extensions.CodeCoverage version 18.11.2. Lock files include the package and its resolved dependencies.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant PullRequestCI as pull-request-ci.yml
  participant SonarWorkflow as sonar.yml
  participant TestProjects
  participant SonarQube
  participant ArtifactStore
  PullRequestCI->>SonarWorkflow: select Sonar eligibility from pull request author
  SonarWorkflow->>SonarQube: validate token and analysis method
  SonarWorkflow->>TestProjects: run test projects with Cobertura coverage
  TestProjects-->>SonarWorkflow: return validated coverage reports
  SonarWorkflow->>SonarQube: run analysis and wait for quality gate
  SonarWorkflow->>ArtifactStore: upload coverage reports
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title identifies the quality-gate work, which is a central part of the pull request. It does not identify Sonar, coverage, or workflow changes, but it remains related and understandable.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@AriusII
AriusII merged commit bd1d105 into main Sep 21, 2026
5 checks passed
@AriusII
AriusII deleted the fix/client-sonar-quality-gate branch September 21, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant