Gate Sonar/Codecov on secret availability + run them safely on fork PRs - #186
Merged
AndreasIgel merged 7 commits intoJul 19, 2026
Merged
AndreasIgel merged 7 commits into
AndreasIgel merged 7 commits into
Conversation
Fork and Dependabot PRs don't receive repository secrets, so the actor-only guard let the SonarCloud and Codecov steps run without their tokens and hard-fail (fail_ci_if_error: true). Expose SONAR_TOKEN and CODECOV_TOKEN as job-level env and gate each dependent step on env.<TOKEN> != '' so they run for same-repo PRs/pushes and are cleanly skipped when secrets are absent. Refs java-helpers#164 Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
Collaborator
Author
|
Should be given to manual reviewer instead, who would start the review on behalf and by that use the corresponding token. |
Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
…roval) Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
Collaborator
Author
|
Implemented as requested: added |
Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Makes external-fork (and Dependabot) PRs stop showing a red
buildcheck for reasons unrelated to the change, and adds a safe way to actually run the secret-backed quality checks (Codecov + SonarCloud) on fork PRs.Fixes #164
Fixes #198
Part 1 — Don't hard-fail fork/Dependabot PRs (issue #164)
The SonarCloud and Codecov steps were gated only on
github.actor != 'dependabot[bot]'. Fork PRs don't receive repository secrets, so the steps ran without tokens and hard-failed (fail_ci_if_error: true). Fix: expose the tokens as job-levelenvand gate each step on the env value being non-empty:On fork/Dependabot PRs secrets resolve to
'', so these steps are skipped cleanly; for same-repo PRs and pushes they run as before (stillfail_ci_if_error: true).Part 2 — Run the quality checks on fork PRs safely (issue #198)
Because fork
pull_requestruns have no secrets, the checks are performed from the base-repository context after the unprivileged CI run. The unprivileged workflow always owns the build, generated-source check, and tests; the privileged workflows only publish their results.Codecov —
.github/workflows/fork-coverage.yml(automatic, no fork code executed).The main CI build (which runs the fork code without secrets) publishes the JaCoCo XML + test reports plus the PR identity as an artifact. A follow-up
workflow_runworkflow downloads only that artifact and has exactly two publishing steps: test execution results and test coverage. Test execution results are uploaded even when the build/test job fails when reports exist, so Codecov receives useful diagnostics. Coverage is published only after a successful CI run, and it cannot make a failed CI check pass. PR #184 setscodecov.require_ci_to_pass: true, so a successful Codecov status also requires the CI workflow to pass.SonarCloud —
.github/workflows/fork-sonar.yml(manual maintainer approval).A
workflow_runstarts only after the fork CI succeeds. It restores the compiled classes and JaCoCo reports produced by that unprivileged run, then has one publishing step for SonarCloud. It does not rebuild or retest fork code whileSONAR_TOKENis available. The workflow checks out the exact successful fork commit so Sonar can inspect its source, and remains gated by thefork-ciGitHub Environment with Required reviewers.A maintainer reviews the diff and clicks Approve; the analysis then runs on their behalf with
SONAR_TOKEN. SonarCloud decorates the PR server-side via the token configured in its project settings.Maintainer setup required
Create a repository Environment named
fork-ci(Settings → Environments) with Required reviewers = the maintainer(s). Without it the Sonar job would not have the mandatory manual safety gate.Why the fork checks can't be seen running on this PR yet
fork-coverage.ymlandfork-sonar.ymluseworkflow_run, and GitHub runsworkflow_run(andpull_request_target) workflows only from the version on the default branch. They live only on this feature branch, so they do not trigger — and the environment approval prompt does not appear — until this PR is merged intomain. After merge, the next fork-PR CI run produces the artifact,fork-sonar.ymlstarts and pauses on thefork-cienvironment for a maintainer to Approve. (Also fixed:workflow_run.pull_requestsis empty for fork runs, so the PR number/branch/base are now read from the CI artifact, and the source is checked out from the base repo'srefs/pull/<n>/head.)Manual runs
Both fork workflows also expose a
workflow_dispatchtrigger with arun_idinput, so a maintainer can start them on demand from the Actions tab for a specific "Java CI with Maven" fork-PR run (e.g. to re-publish coverage or run Sonar). Thefork-cienvironment approval still applies to the Sonar dispatch.Validation
actionlintpasses onmaven.yml,fork-coverage.yml,fork-sonar.yml.fork-cienvironment), as noted above.Maintainer TODOs (required before the fork checks work)
fork-ciEnvironment (Settings → Environments → New environment →fork-ci) and add yourself (a maintainer) under Required reviewers.fork-sonar.ymlreferences this environment as its approval gate; without it the Sonar job would run untrusted fork code with secrets automatically, which is unsafe.pull-requests: write(Drop unnecessary pull-requests: write scope from the Maven CI job #187) and behind the fork-Sonar design.SONAR_TOKENandCODECOV_TOKENrepository secrets exist (they are already used by the main CI); no new secrets are introduced by this PR.