-
-
Notifications
You must be signed in to change notification settings - Fork 0
36 lines (36 loc) · 1.17 KB
/
Copy pathsonarqube.yml
File metadata and controls
36 lines (36 loc) · 1.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# SonarQube Cloud (SonarCloud) static analysis. Analysis scope + exclusions live
# in sonar-project.properties. Requires the SONAR_TOKEN repository secret
# (Settings -> Secrets and variables -> Actions) and a SonarCloud project:
# https://sonarcloud.io/project/overview?id=hyperpolymath_lithoglyph
# Mirrors the boj-server arrangement.
name: SonarQube
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
sonarqube:
name: SonarQube
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
with:
fetch-depth: 0 # full history for accurate new-code detection
- name: SonarQube Scan
uses: SonarSource/sonarqube-scan-action@v8.2.2
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}