Repository navigation
Follow-up quality gate #41-#49 - #52
Conversation
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (11)
Limit details: You’ve used all 10 included reviews currently available. 📝 WalkthroughWalkthroughThe pull request updates Sonar workflow eligibility and enforcement. It adds mandatory token validation, unconditional analysis steps, Cobertura coverage generation and validation, report artifact upload, and centralized coverage package references for test projects. ChangesSonar CI workflow
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant PullRequestCI as pull-request-ci.yml
participant SonarWorkflow as sonar.yml
participant TestProjects
participant SonarQube
participant ArtifactStore
PullRequestCI->>SonarWorkflow: select Sonar eligibility from pull request author
SonarWorkflow->>SonarQube: validate token and analysis method
SonarWorkflow->>TestProjects: run test projects with Cobertura coverage
TestProjects-->>SonarWorkflow: return validated coverage reports
SonarWorkflow->>SonarQube: run analysis and wait for quality gate
SonarWorkflow->>ArtifactStore: upload coverage reports
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
*.Tests.csprojprojects, using the officially supported Cobertura output.sonar.cs.cobertura.reportsPaths; collector staging copies are deliberately excluded to prevent duplicate coverage import.sonarscanner endwhen a final report is missing, empty, malformed, or not Cobertura.sonar.qualitygate.wait=truewith a 300-second timeout. A red or unavailable quality-gate result now fails the workflow.SONAR_TOKENfor an authorized analysis instead of emitting a successful skip, and fails closed if the analysis-method check cannot be verified.pull_requesttrigger; forks and Dependabot PRs are excluded before any repository secret is forwarded. Dependabot is identified from the PR author rather than the rerun actor.Why
PRs #41 through #49 all completed with the Sonar job skipped because the repository variable
SONAR_CI_ENABLEDis absent, while the repository secret namedSONAR_TOKENis present. The reusable workflow also defaulted the quality-gate wait to false and no longer collected or imported coverage. This restores the coverage behavior introduced by 019814a while correcting its scanner/report handling and making the gate enforceable.Validation
dotnet restore CheatEngine.Client.slnx --locked-modedotnet build CheatEngine.Client.slnx --configuration Release --no-restore --no-incremental --disable-build-servers --warnaserroractionlint1.7.12 passed after SHA-256 verification.git diff --checkpassed.Activation after merge — intentionally not performed by this PR
Enable the guarded Sonar callers only when ready:
This PR does not alter
SONAR_TOKENor the feature variable. After enabling it, verify a same-repository PR and a main push; consider requiring the resultingSonar / Analyzecheck alongsideCI / Gatein the main-branch ruleset.Summary by CodeRabbit