From 63679e8588fb781f321adf85eb07453aae97a066 Mon Sep 17 00:00:00 2001 From: AriusII Date: Mon, 21 Sep 2026 22:37:44 +0200 Subject: [PATCH] Remove SonarCloud CI integration --- .github/workflows/main-ci.yml | 9 -- .github/workflows/pull-request-ci.yml | 12 -- .github/workflows/sonar.yml | 210 -------------------------- 3 files changed, 231 deletions(-) delete mode 100644 .github/workflows/sonar.yml diff --git a/.github/workflows/main-ci.yml b/.github/workflows/main-ci.yml index d824f3c..13a965c 100644 --- a/.github/workflows/main-ci.yml +++ b/.github/workflows/main-ci.yml @@ -34,12 +34,3 @@ jobs: ci: name: CI uses: ./.github/workflows/ci.yml - - # Main analysis is the SonarQube Cloud baseline for pull-request new-code comparisons. - sonar: - name: Sonar - needs: ci - if: vars.SONAR_CI_ENABLED == 'true' && github.ref == 'refs/heads/main' - uses: ./.github/workflows/sonar.yml - secrets: - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/pull-request-ci.yml b/.github/workflows/pull-request-ci.yml index c356a2b..60ba7b7 100644 --- a/.github/workflows/pull-request-ci.yml +++ b/.github/workflows/pull-request-ci.yml @@ -33,18 +33,6 @@ jobs: if: github.event.pull_request.draft == false uses: ./.github/workflows/ci.yml - # Fork and Dependabot pull requests receive no repository secret, so Sonar skips them. - sonar: - name: Sonar - needs: ci - if: >- - vars.SONAR_CI_ENABLED == 'true' - && github.event.pull_request.head.repo.full_name == github.repository - && github.event.pull_request.user.login != 'dependabot[bot]' - uses: ./.github/workflows/sonar.yml - secrets: - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} - lint-workflows: name: Lint workflows if: github.event.pull_request.draft == false diff --git a/.github/workflows/sonar.yml b/.github/workflows/sonar.yml deleted file mode 100644 index 3474a27..0000000 --- a/.github/workflows/sonar.yml +++ /dev/null @@ -1,210 +0,0 @@ -name: Sonar - -on: - workflow_call: - inputs: - project-key: - description: SonarQube Cloud project key. - type: string - default: CheatEngineNet_CheatEngine.Client - organization: - description: SonarQube Cloud organization key. - type: string - default: cheatenginenet - secrets: - SONAR_TOKEN: - description: SonarQube Cloud token for protected, same-repository analysis. - required: true - -permissions: - contents: read - -defaults: - run: - shell: pwsh - -env: - DOTNET_NOLOGO: true - DOTNET_CLI_TELEMETRY_OPTOUT: true - MSBUILDDISABLENODEREUSE: true - SONAR_SCANNER_VERSION: 11.3.0 - -jobs: - analyze: - name: Analyze - if: github.event_name != 'merge_group' - runs-on: windows-latest - timeout-minutes: 40 - env: - SONAR_PROJECT_KEY: ${{ inputs.project-key }} - SONAR_ORGANIZATION: ${{ inputs.organization }} - - steps: - - name: Require Sonar token - env: - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} - run: | - if ([string]::IsNullOrWhiteSpace($env:SONAR_TOKEN)) { - throw 'SONAR_TOKEN is required when SONAR_CI_ENABLED is true.' - } - - - name: Check analysis method - env: - SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} - run: | - $uri = "https://sonarcloud.io/api/settings/values?component=$env:SONAR_PROJECT_KEY&keys=sonar.autoscan.enabled" - try { - $response = Invoke-RestMethod -Uri $uri -Headers @{ Authorization = "Bearer $env:SONAR_TOKEN" } ` - -TimeoutSec 30 -MaximumRetryCount 2 -RetryIntervalSec 3 - } - catch { - throw "Could not verify the analysis method of $env:SONAR_PROJECT_KEY. $($_.Exception.Message)" - } - - if (@($response.settings | Where-Object { $_.key -eq 'sonar.autoscan.enabled' -and $_.value -eq 'true' })) { - Write-Host "::error::Automatic Analysis is enabled on $env:SONAR_PROJECT_KEY, so SonarQube Cloud rejects CI analysis. Turn it off in Administration, Analysis Method." - exit 1 - } - - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 - persist-credentials: false - - - name: Set up JDK 21 - uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 - with: - distribution: zulu - java-version: '21' - - - name: Install pinned .NET SDK - uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 - with: - global-json-file: global.json - cache: true - cache-dependency-path: | - **/packages.lock.json - Directory.Packages.props - - - name: Install scanner - run: >- - dotnet tool install dotnet-sonarscanner --tool-path "$env:RUNNER_TEMP/sonar-scanner" - --version $env:SONAR_SCANNER_VERSION - - - name: Restore locked dependency graph - run: dotnet restore CheatEngine.Client.slnx --locked-mode - - - name: Begin analysis - env: - SONARQUBE_SCANNER_PARAMS: '{"sonar.token":"${{ secrets.SONAR_TOKEN }}"}' - run: | - # These findings conflict with deliberate repository contracts. Keep them in the scanner configuration so - # production and test sources do not need Sonar-only attributes or code changes. - $ignoredIssues = @( - @{ Key = 'noLinq'; Rule = 'csharpsquid:S3267'; Resource = '**/*.cs' } - @{ Key = 'unsafeInterop'; Rule = 'csharpsquid:S6640'; Resource = '**/*.cs' } - @{ Key = 'nullableFlow'; Rule = 'csharpsquid:S8970'; Resource = '**/*.cs' } - @{ Key = 'apiOverloadLayout'; Rule = 'csharpsquid:S4136'; Resource = 'libs/**' } - @{ Key = 'generatorInstances'; Rule = 'csharpsquid:S2325'; Resource = 'source-generators/**' } - @{ Key = 'emittedFragments'; Rule = 'csharpsquid:S1192'; Resource = 'source-generators/**' } - @{ Key = 'generatorComments'; Rule = 'csharpsquid:S125'; Resource = 'source-generators/**' } - @{ Key = 'testReflection'; Rule = 'csharpsquid:S3011'; Resource = 'tests/**' } - @{ Key = 'testLiterals'; Rule = 'csharpsquid:S1192'; Resource = 'tests/**' } - @{ Key = 'testGc'; Rule = 'csharpsquid:S1215'; Resource = 'tests/**' } - @{ Key = 'testStaticHooks'; Rule = 'csharpsquid:S2696'; Resource = 'tests/**' } - @{ Key = 'testDoubleDispose'; Rule = 'csharpsquid:S3966'; Resource = 'tests/**' } - @{ Key = 'testBooleanTables'; Rule = 'csharpsquid:S1125'; Resource = 'tests/**' } - @{ Key = 'testComplexity'; Rule = 'csharpsquid:S3776'; Resource = 'tests/**' } - @{ Key = 'testParameters'; Rule = 'csharpsquid:S107'; Resource = 'tests/**' } - @{ Key = 'testMarkerClasses'; Rule = 'csharpsquid:S1118'; Resource = 'tests/**' } - @{ Key = 'testDuplicateScenarios'; Rule = 'csharpsquid:S4144'; Resource = 'tests/**' } - @{ Key = 'testFixedDoubles'; Rule = 'csharpsquid:S3400'; Resource = 'tests/**' } - @{ Key = 'testComments'; Rule = 'csharpsquid:S125'; Resource = 'tests/**' } - ) - $arguments = @( - "/k:$env:SONAR_PROJECT_KEY" - "/o:$env:SONAR_ORGANIZATION" - '/d:sonar.exclusions=artifacts/**,tests/CheatEngine.Client.Benchmarks/**' - '/d:sonar.cs.cobertura.reportsPaths=artifacts/sonar-test-results/*/coverage.cobertura.xml' - "/d:sonar.issue.ignore.multicriteria=$(($ignoredIssues.Key) -join ',')" - '/d:sonar.qualitygate.wait=true' - '/d:sonar.qualitygate.timeout=300' - ) - foreach ($issue in $ignoredIssues) { - $arguments += "/d:sonar.issue.ignore.multicriteria.$($issue.Key).ruleKey=$($issue.Rule)" - $arguments += "/d:sonar.issue.ignore.multicriteria.$($issue.Key).resourceKey=$($issue.Resource)" - } - & "$env:RUNNER_TEMP/sonar-scanner/dotnet-sonarscanner.exe" begin @arguments - - - name: Build - run: >- - dotnet build CheatEngine.Client.slnx --configuration Release --no-restore --no-incremental - --disable-build-servers --warnaserror - - - name: Run tests with Microsoft Testing Platform coverage - run: | - $projects = @(Get-ChildItem -Path tests -Filter '*.Tests.csproj' -Recurse -File | Sort-Object FullName) - if ($projects.Count -eq 0) { - throw 'No *.Tests.csproj project found under tests.' - } - - foreach ($project in $projects) { - $results = Join-Path 'artifacts/sonar-test-results' $project.BaseName - $coverage = [IO.Path]::GetFullPath((Join-Path $results 'coverage.cobertura.xml')) - $options = @( - '--project', $project.FullName, - '--configuration', 'Release', - '--no-build', '--no-restore', - '--report-trx', - '--results-directory', $results, - '--coverage', - '--coverage-output', $coverage, - '--coverage-output-format', 'cobertura', - '--fail-skips', 'on' - ) - dotnet test @options - if ($LASTEXITCODE -ne 0) { - throw "Microsoft Testing Platform failed for '$($project.FullName)' with exit code $LASTEXITCODE." - } - } - - - name: Verify coverage reports - run: | - $projects = @(Get-ChildItem -Path tests -Filter '*.Tests.csproj' -Recurse -File) - $reports = @($projects | ForEach-Object { - Join-Path (Join-Path 'artifacts/sonar-test-results' $_.BaseName) 'coverage.cobertura.xml' - }) - $missingReports = @($reports | Where-Object { -not (Test-Path -LiteralPath $_ -PathType Leaf) }) - if ($missingReports.Count -gt 0) { - throw "Microsoft Testing Platform did not produce Cobertura coverage report(s): $($missingReports -join ', ')." - } - - foreach ($report in $reports) { - try { - $coverage = [xml](Get-Content -LiteralPath $report -Raw) - } - catch { - throw "Coverage report '$report' is not valid XML. $($_.Exception.Message)" - } - - if ((Get-Item -LiteralPath $report).Length -eq 0 -or $coverage.DocumentElement.Name -ne 'coverage') { - throw "Coverage report '$report' is not a Cobertura report." - } - } - - Write-Host "Verified $($reports.Count) Cobertura coverage report(s)." - - - name: End analysis - env: - SONARQUBE_SCANNER_PARAMS: '{"sonar.token":"${{ secrets.SONAR_TOKEN }}"}' - run: '& "$env:RUNNER_TEMP/sonar-scanner/dotnet-sonarscanner.exe" end' - - - name: Upload Sonar coverage reports - if: ${{ !cancelled() }} - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: sonar-coverage - path: artifacts/sonar-test-results/*/coverage.cobertura.xml - if-no-files-found: error - retention-days: 14