Tighten coverage gates (require CI to pass; measure mapper logic) #408
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow will build a Java project with Maven, and cache/restore any dependencies to improve the workflow execution time | |
| # For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-java-with-maven | |
| # This workflow uses actions that are not certified by GitHub. | |
| # They are provided by a third-party and are governed by | |
| # separate terms of service, privacy policy, and support | |
| # documentation. | |
| name: Java CI with Maven | |
| on: | |
| push: | |
| branches: [ "main" ] | |
| pull_request: | |
| branches: [ "main" ] | |
| types: [opened, synchronize, reopened] | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| checks: write | |
| # Expose secret-backed tokens as env so steps can be gated on their | |
| # availability. On fork/Dependabot PRs secrets are withheld and resolve to | |
| # an empty string, so the dependent steps are skipped rather than failing. | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} | |
| CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| with: | |
| fetch-depth: 0 # Shallow clones should be disabled for better SonarCloud analysis | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4.8.0 | |
| with: | |
| java-version: '17' | |
| distribution: 'zulu' | |
| cache: maven | |
| - name: Cache SonarCloud packages | |
| uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 | |
| with: | |
| path: ~/.sonar/cache | |
| key: ${{ runner.os }}-sonar | |
| restore-keys: ${{ runner.os }}-sonar | |
| - name: Cache Maven packages | |
| uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 | |
| with: | |
| path: ~/.m2 | |
| key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }} | |
| restore-keys: ${{ runner.os }}-m2 | |
| - name: Build with Maven | |
| run: mvn -B install -Pmetrics --file pom.xml | |
| - name: Check for uncommitted generated source changes | |
| if: github.event_name == 'pull_request' | |
| run: | | |
| echo "Checking for uncommitted generated source changes..." | |
| # Check if there are any changes in generated-sources directories | |
| if git diff --name-only HEAD | grep -E "target/generated-sources/"; then | |
| echo "❌ ERROR: Found uncommitted generated source changes!" | |
| echo "" | |
| echo "The following generated files have changed:" | |
| git diff --name-only HEAD | grep -E "target/generated-sources/" | sed 's/^/ /' | |
| echo "" | |
| echo "Please commit these changes to the repository:" | |
| echo " git add target/generated-sources/" | |
| echo " git commit -m \"Update generated sources\"" | |
| echo "" | |
| exit 1 | |
| else | |
| echo "✅ No uncommitted generated source changes found" | |
| fi | |
| - name: Package Sonar analysis inputs (fork PRs) | |
| if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository | |
| env: | |
| # Pass PR metadata through the environment (never interpolate the | |
| # attacker-controlled head ref/sha directly into the shell script). | |
| PR_NUMBER: ${{ github.event.number }} | |
| PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }} | |
| PR_HEAD_REF: ${{ github.event.pull_request.head.ref }} | |
| PR_BASE_REF: ${{ github.event.pull_request.base.ref }} | |
| run: | | |
| mkdir -p sonar-analysis-data | |
| cp -a core/target/classes sonar-analysis-data/core-classes 2>/dev/null || true | |
| cp -a processor/target/classes sonar-analysis-data/processor-classes 2>/dev/null || true | |
| cp -a core/target/site/jacoco/jacoco.xml sonar-analysis-data/core-jacoco.xml 2>/dev/null || true | |
| cp -a processor/target/site/jacoco/jacoco.xml sonar-analysis-data/processor-jacoco.xml 2>/dev/null || true | |
| { | |
| printf 'pr_number=%s\n' "$PR_NUMBER" | |
| printf 'pr_head_sha=%s\n' "$PR_HEAD_SHA" | |
| printf 'pr_head_ref=%s\n' "$PR_HEAD_REF" | |
| printf 'pr_base_ref=%s\n' "$PR_BASE_REF" | |
| } > sonar-analysis-data/pr-event.env | |
| - name: Upload Sonar analysis inputs (fork PRs) | |
| if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | |
| with: | |
| name: sonar-analysis-inputs | |
| path: sonar-analysis-data/ | |
| if-no-files-found: warn | |
| - name: SonarCloud Analysis | |
| # Skip when SONAR_TOKEN is unavailable (fork/Dependabot PRs). | |
| if: env.SONAR_TOKEN != '' | |
| run: mvn -B org.sonarsource.scanner.maven:sonar-maven-plugin:sonar --file pom.xml | |
| - name: Upload JaCoCo HTML report (processor) | |
| if: always() | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | |
| with: | |
| name: jacoco-report-html-processor | |
| path: processor/target/site/jacoco/ | |
| if-no-files-found: warn | |
| - name: Upload JaCoCo XML report (processor) | |
| if: always() | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | |
| with: | |
| name: jacoco-report-xml-processor | |
| path: processor/target/site/jacoco/jacoco.xml | |
| if-no-files-found: warn | |
| # For PRs from forks, secrets are withheld so the direct Codecov steps | |
| # below are skipped. Instead publish the coverage data (plus the PR | |
| # identity) as an artifact; the privileged fork-coverage.yml workflow | |
| # (triggered on workflow_run, in the base-repo context) consumes it and | |
| # uploads to Codecov without ever executing fork code. | |
| - name: Assemble Codecov payload (fork PRs) | |
| if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository | |
| env: | |
| # Pass PR metadata through the environment (never interpolate the | |
| # attacker-controlled head ref/sha directly into the shell script). | |
| PR_NUMBER: ${{ github.event.number }} | |
| PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }} | |
| PR_HEAD_REF: ${{ github.event.pull_request.head.ref }} | |
| run: | | |
| mkdir -p codecov-payload/surefire codecov-payload/failsafe | |
| cp -f processor/target/site/jacoco/jacoco.xml codecov-payload/ 2>/dev/null || true | |
| cp -f processor/target/surefire-reports/*.xml codecov-payload/surefire/ 2>/dev/null || true | |
| cp -f processor/target/failsafe-reports/*.xml codecov-payload/failsafe/ 2>/dev/null || true | |
| { | |
| printf 'pr_number=%s\n' "$PR_NUMBER" | |
| printf 'pr_head_sha=%s\n' "$PR_HEAD_SHA" | |
| printf 'pr_head_ref=%s\n' "$PR_HEAD_REF" | |
| } > codecov-payload/pr-event.env | |
| - name: Upload Codecov payload artifact (fork PRs) | |
| if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name != github.repository | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | |
| with: | |
| name: codecov-payload | |
| path: codecov-payload/ | |
| if-no-files-found: warn | |
| - name: Upload test results to Codecov (processor) | |
| # Skip when CODECOV_TOKEN is unavailable (fork/Dependabot PRs). | |
| if: always() && env.CODECOV_TOKEN != '' | |
| uses: codecov/test-results-action@47f89e9acb64b76debcd5ea40642d25a4adced9f # v1.1.1 | |
| with: | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| files: | | |
| processor/target/surefire-reports/*.xml | |
| processor/target/failsafe-reports/*.xml | |
| fail_ci_if_error: true | |
| verbose: false | |
| - name: Upload coverage to Codecov (processor) | |
| # Skip when CODECOV_TOKEN is unavailable (fork/Dependabot PRs). | |
| if: always() && env.CODECOV_TOKEN != '' | |
| uses: codecov/codecov-action@015f24e6818733317a2da2edd6290ab26238649a # v5.0.7 | |
| with: | |
| fail_ci_if_error: true | |
| files: processor/target/site/jacoco/jacoco.xml | |
| flags: processor | |
| name: codecov-upload | |
| verbose: false | |
| token: ${{ secrets.CODECOV_TOKEN }} |